SonicWall SMA1000 零日漏洞遭積極利用,引發自訂惡意軟件攻擊活動

SonicWall SMA1000 zero-day CVE-2026-15409 CVE-2026-15410 UTA0533 KnuckleBall malware CISA KEV catalog
J
James Okoro

Ethical Hacking & Threat Intelligence Editor

 
2026年7月21日
4 分鐘閱讀
SonicWall SMA1000 零日漏洞遭積極利用,引發自訂惡意軟件攻擊活動

TL;DR

• SonicWall SMA1000 系列設備正遭受兩個關鍵零日漏洞的積極攻擊。 • 攻擊者透過串聯 CVE-2026-15409 與 CVE-2026-15410 獲取 Root 級別控制權。 • 威脅組織 UTA0533 正部署名為「KnuckleBall」的自訂惡意軟件以維持持久存取。 • CISA 已將上述兩個漏洞列入「已知被利用漏洞」(KEV) 目錄。

SonicWall SMA1000 零日漏洞遭積極利用,引發自訂惡意軟件攻擊活動

安全研究人員與政府機構已證實,SonicWall Secure Mobile Access (SMA) 1000 系列設備中的兩個關鍵零日漏洞正遭到積極利用。在修補程式發佈前的數週內,攻擊者早已滲透其中,利用這些漏洞獲取企業網絡的 Root 級別存取權限。其後果包括:憑證遭竊、自訂惡意軟件部署,以及為橫向移動敞開大門。

這些漏洞分別被編號為 CVE-2026-15409CVE-2026-15410,它們有效地瓦解了標準的身份驗證協議。截至 2026 年 7 月 14 日,美國網絡安全與基礎設施安全局 (CISA) 已將兩者納入其「已知被利用漏洞」(KEV) 目錄,向聯邦機構與私人企業發出明確信號:立即修補,否則後果自負。

漏洞剖析

攻擊鏈始於 CVE-2026-15409,這是一個極度危險的伺服器端請求偽造 (SSRF) 漏洞。其 CVSS 評分高達 10.0 分,允許未經身份驗證的攻擊者發起基於 WebSocket 的隧道,連接至設備上運行的本地服務。簡單來說,攻擊者可以與原本不應暴露於公共互聯網的內部服務進行通訊。

一旦取得立足點,他們便會轉向利用 CVE-2026-15410 進行權限提升。這是一個隱藏在設備「remove_hotfix」工作流程中的路徑遍歷漏洞。透過串聯這兩個漏洞,互聯網上的任何陌生人都能搖身一變成為 Root 級別管理員,完全掌控 SMA 1000 設備。

SonicWall SMA1000 零日漏洞遭積極利用,引發自訂惡意軟件攻擊活動

圖片來源:Dark Reading

幕後黑手及其目的

根據包括 Rapid7 MDR 團隊 在內的分析師指出,這場攻擊活動始於 2026 年 6 月 22 日左右。幕後的威脅組織 UTA0533 不僅僅是試探,他們還部署了一種名為「KnuckleBall」的自訂惡意軟件。

KnuckleBall 相當棘手,它會將惡意代碼直接注入合法的系統進程中以隱藏蹤跡。攻擊者被發現同時使用名為「OrangeTail」的 Java WebShell 以及名為「Suo5」的開源代理工具。這些不僅是玩具,更是用於持久化、憑證收集與深度網絡隧道的工具。我們甚至觀察到 Inc 勒索軟件組織也加入其中,利用這些漏洞進行全面的網絡入侵與數據外洩。

影響與補救措施

受影響的硬件包括 SonicWall SMA 1000 系列,特別是 6210、7210 及 8200v 型號。由於這些設備是安全遠端存取的守門人,其風險極高。

漏洞 類型 嚴重程度
CVE-2026-15409 SSRF 關鍵 (10.0)
CVE-2026-15410 權限提升 高 (7.2)

SonicWall 已發佈針對平台的修補程式以填補這些漏洞。如果您正在使用這些設備,請務必前往 SonicWall 官方 PSIRT 公告 並立即更新韌體。

行動計劃:

  • 立即修補: 為您所有 SMA 1000 設備套用最新的修補程式。
  • 審核日誌: 留意可疑的 WebSocket 連接,或與「remove_hotfix」工作流程相關的異常進程活動。
  • 輪換憑證: 做好最壞打算。如果用戶曾透過受感染的 SMA 設備進行身份驗證,請立即強制重設密碼。
  • 鎖定管理控制台: 僅限受信任的內部網絡存取管理介面,從源頭阻斷 SSRF 與路徑遍歷嘗試。

總結

這場攻擊活動凸顯了一個令人擔憂的趨勢:老練的攻擊者正越來越擅長將我們的邊界防禦轉化為攻擊武器。正如 Volexity 最近指出的,透過邊緣設備進行流量隧道傳輸是一種隱蔽的高超手段。當您濫用本應用於保護網絡的設備時,實際上已摧毀了整個企業的信任模型。

從 6 月下旬的初步入侵到 7 月中旬發佈修補程式,這三週的空窗期在安全領域中如同漫長的一生。在此期間,許多組織基本上處於盲目狀態,未察覺其邊界已被攻破。「KnuckleBall」惡意軟件的出現與勒索軟件組織的參與,是一個發人深省的提醒:即使您的安全設備看起來運作正常,主動的威脅獵捕仍是不可或缺的。

目前,首要任務很簡單:將所有舊款與現行的 SMA 1000 設備更新至最新韌體。如果您無法立即修補,請將管理介面與外部網絡隔離。同時,持續監控對外流量——如果您在修補前已遭入侵,系統中可能仍殘留等待指令的惡意程式。

J
James Okoro

Ethical Hacking & Threat Intelligence Editor

 

James Okoro is a certified ethical hacker (CEH) and cybersecurity journalist with a background in military intelligence. After serving as a cyber operations analyst, he transitioned into the private sector, working as a threat intelligence consultant before finding his voice as a writer. James has covered major data breaches, ransomware campaigns, and state-sponsored cyberattacks for several leading security publications. He brings a tactical, insider perspective to his reporting on the ever-evolving threat landscape.

相關新聞

Private Internet Access Updates WireGuard and OpenVPN Protocol Implementations to Strengthen Remote Access Security
WireGuard VPN protocol

Private Internet Access Updates WireGuard and OpenVPN Protocol Implementations to Strengthen Remote Access Security

Private Internet Access integrates WireGuard protocol across its suite for faster, more secure remote access. Learn how this update improves your VPN connection.

作者: Marcus Chen 2026年7月20日 4 分鐘閱讀
common.read_full_article
Citrix NetScaler Gateway Under Active Exploitation for Session Hijacking and Authentication Bypass Attacks
CVE-2023-4966

Citrix NetScaler Gateway Under Active Exploitation for Session Hijacking and Authentication Bypass Attacks

Discover how the Citrix Bleed (CVE-2023-4966) vulnerability allows session hijacking. Learn how to patch your NetScaler Gateway against authentication bypass.

作者: Elena Voss 2026年7月19日 4 分鐘閱讀
common.read_full_article
Hackers Exploiting CitrixBleed 2 to Hijack Session Tokens and Bypass Enterprise MFA Protections
CitrixBleed 2

Hackers Exploiting CitrixBleed 2 to Hijack Session Tokens and Bypass Enterprise MFA Protections

Hackers are exploiting CitrixBleed 2 (CVE-2025-5777) to hijack session tokens and bypass MFA. Patch your NetScaler instances immediately to prevent breach.

作者: James Okoro 2026年7月18日 3 分鐘閱讀
common.read_full_article
New Industry Report Identifies Shadow IT and Remote Infrastructure Risks as Critical Enterprise Security Threats
shadow IT

New Industry Report Identifies Shadow IT and Remote Infrastructure Risks as Critical Enterprise Security Threats

Discover why shadow IT and remote infrastructure are critical enterprise security threats. Learn how to secure your decentralized network against modern attacks.

作者: Marcus Chen 2026年7月17日 5 分鐘閱讀
common.read_full_article