UTA0533 is a hands-on-keyboard threat actor known for compromising SonicWall SMA appliances to pivot into internal networks via VPN gateways.
Analyst brief
UTA0533 is a hands-on-keyboard threat actor targeting SonicWall SMA appliances for initial access since at least late June 2026. The actor focuses on compromised VPN gateways to pivot into internal networks and exfiltrate data. Key TTPs include routing malicious traffic through 200+ ExpressVPN and Mullvad exit nodes, and using tools like Kali Linux for lateral movement, often leaking hostnames in the process. Defenders should scrutinize SonicWall SMA logs for anomalous authentications and hunt for lateral movement originating from hundreds of commercial VPN exit IPs.
UTA0533
unknown
UTA0533 has been linked to compromised SonicWall SMA appliances, with exploitation beginning on June 22, 2026. The actor routed traffic through ExpressVPN and Mullvad exit nodes, utilizing over 200 IP addresses. Notably, several attacker hostnames, including a Kali Linux machine, were leaked during lateral movement, indicating hands-on-keyboard intrusion.
What devices does UTA0533 target for initial access?+
UTA0533 targets SonicWall SMA appliances for initial access.
What should defenders focus on to detect UTA0533 activity?+
Defenders should scrutinize SonicWall SMA logs for anomalous authentications and hunt for lateral movement originating from hundreds of commercial VPN exit IPs like ExpressVPN and Mullvad.