APT / THREAT GROUP
UTA0533
1
aliases
Last seen:Jul 29, 2026
Intelligence Profile
UTA0533 has been linked to compromised SonicWall SMA appliances, with exploitation beginning on June 22, 2026. The actor routed traffic through ExpressVPN and Mullvad exit nodes, utilizing over 200 IP addresses. Notably, several attacker hostnames, including a Kali Linux machine, were leaked during lateral movement, indicating hands-on-keyboard intrusion.
Threat Analysis
UTA0533 is a known-sophistication threat actor of undetermined national origin, engaged in cyber operations with a primary motivation of unknown activity patterns.
Intelligence Reports Mentioning UTA0533
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
SecurityWeek· Jul 20, 2026
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
The Hacker News· Jul 19, 2026
External References
Quick Facts
TypeAPT / Threat Group
Aliases1
SourceMalpedia
Also Known As
UTA0533
Research Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.