{"id":862,"date":"2026-07-21T14:00:39","date_gmt":"2026-07-21T08:30:39","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=862"},"modified":"2026-08-19T11:05:33","modified_gmt":"2026-08-19T05:35:33","slug":"inside-uta0533s-sonicwall-sma-malware-toolkit","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/","title":{"rendered":"Inside UTA0533 SonicWall SMA Malware Toolkit: ROOTRUN, KNUCKLEBALL and ORANGETAIL"},"content":{"rendered":"<h2>Introduction<\/h2>\n<p>The UTA0533 SonicWall SMA malware toolkit shows how attackers extended the impact of the SonicWall SMA zero-day campaign beyond initial exploitation. Our previous article examined how CVE-2026-15409 and CVE-2026-15410 enabled attackers to compromise SonicWall SMA 1000 series VPN appliances before public disclosure. It focused on affected products, vulnerability details and immediate remediation.<\/p>\n<p>However, the vulnerabilities only provided initial access. After obtaining root privileges, UTA0533 deployed malware and persistence mechanisms designed specifically for SonicWall SMA appliances.<\/p>\n<p>The toolkit allowed the attackers to:<\/p>\n<ul>\n<li>Maintain privileged command execution.<\/li>\n<li>Inject Java payloads into a legitimate SonicWall appliance process.<\/li>\n<li>Reload <strong>KNUCKLEBALL<\/strong> and its embedded Java payloads after a reboot.<\/li>\n<li>Expose externally accessible routes to the <strong>Suo5<\/strong> proxy and <strong>ORANGETAIL<\/strong> web shell.<\/li>\n<li>Separately, UTA0533 placed scripts on one appliance that appeared designed to capture unencrypted LDAP traffic.<\/li>\n<\/ul>\n<p>These findings show why appliance forensics must accompany vulnerability remediation. Patching closes the original security flaw, but it does not automatically remove malware or reverse configuration changes introduced before the update.<\/p>\n    \t\t<div class=\"hts-messages hts-messages--alert  hts-messages--withtitle  \"   >\r\n    \t\t\t<span class=\"hts-messages__title\">Key Facts<\/span>    \t\t\t    \t\t\t\t<p>\r\n    \t\t\t\t\t<\/p>\n<ul>\n<li><strong>Threat actor<\/strong>: UTA0533<\/li>\n<li><strong>Target<\/strong>: SonicWall SMA 1000 series VPN appliances<\/li>\n<li><strong>Attack type<\/strong>: Zero-day exploitation followed by malware deployment<\/li>\n<li><strong>Malware and tools<\/strong>: <strong>ROOTRUN<\/strong>, <strong>KNUCKLEBALL<\/strong>, <strong>Suo5<\/strong> and <strong>ORANGETAIL<\/strong><\/li>\n<li><strong>Persistence, execution and access techniques<\/strong>: Startup-script modification, Java process injection and <code>NGINX Unit<\/code> route modification<\/li>\n<li><strong>Confirmed<\/strong>: Root-level compromise and custom malware deployment<\/li>\n<li><strong>Not confirmed<\/strong>: Credential theft, data exfiltration or successful lateral movement<\/li>\n<\/ul>\n<p>    \t\t\t\t<\/p>\r\n    \t\t\t    \t\t\t\r\n    \t\t<\/div><!-- \/.ht-shortcodes-messages -->\r\n    \t\t\n<h3>UTA0533 SonicWall SMA Malware Toolkit at a Glance<\/h3>\n<table style=\"font-weight: 400;\" data-tablestyle=\"MsoTableGrid\" data-tablelook=\"1696\" aria-rowcount=\"5\">\n<tbody>\n<tr aria-rowindex=\"1\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Component<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Primary function<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Key technique<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:2,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"2\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">ROOTRUN<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Root-level command execution<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Uses a Linux\u00a0<code>setuid<\/code>\u00a0binary<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"3\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">KNUCKLEBALL<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Java payload loading<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Injects payloads through the Java Attach API<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"4\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">Suo5<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Traffic proxying<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Could relay traffic through the compromised appliance<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<tr aria-rowindex=\"5\">\n<td data-celllook=\"0\"><b><span data-contrast=\"auto\">ORANGETAIL<\/span><\/b><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Remote command execution<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<td data-celllook=\"0\"><span data-contrast=\"auto\">Operates as a Java web shell reachable through modified <code>NGINX Unit<\/code> routes<\/span><span data-ccp-props=\"{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:1,&quot;335551620&quot;:0,&quot;335559738&quot;:0,&quot;335559739&quot;:0}\">\u00a0<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Why the UTA0533 SonicWall SMA Malware Matters More Than the Zero-Day<\/h2>\n<p>Vendors may eventually release patches for zero-day vulnerabilities, but malware installed during the exploitation window can remain active after administrators apply the fix.<\/p>\n<p>In this campaign, UTA0533 used root access to deploy tooling that could:<\/p>\n<ul>\n<li>Reload <strong>KNUCKLEBALL<\/strong> and its embedded Java payloads after a reboot through a modified startup script.<\/li>\n<li>Operate inside a legitimate SonicWall Java process.<\/li>\n<li>Provide continued root-level command execution while <strong>ROOTRUN<\/strong> remained installed and accessible.<\/li>\n<li>Support additional post-exploitation activity.<\/li>\n<\/ul>\n<p>This campaign shows how <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-threat-actor-in-cyber-security\/\">threat actors<\/a> can build implants for specific VPN and edge-appliance environments instead of relying exclusively on commodity tools. Such malware may be harder to identify because it operates inside legitimate appliance processes and uses modified application routes<\/p>\n<p>Consequently, organizations should treat patching as the start of recovery, not the end. Security teams must also review startup scripts, privileged binaries, web server configurations and other persistence locations.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Sonic-Wall-SMA1000-Zero-Day-Patch-150x150-1.webp?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>SonicWall SMA1000 Zero-Day: CVE-2026-15409 & CVE-2026-15410 Explained<\/h4><p>Learn how attackers exploited SonicWall SMA zero-days, affected appliances, and the recommended remediation steps.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/sonicwall-sma1000-zero-day-cve-2026-15409-cve-2026-15410\/\" aria-label=\"SonicWall SMA1000 Zero-Day: CVE-2026-15409 & CVE-2026-15410 Explained\"><\/a><\/div><\/div><\/div>\n<h2>Breaking Down the UTA0533 SonicWall SMA Malware Toolkit<\/h2>\n<h3>ROOTRUN<\/h3>\n<p>Investigators identified an ELF binary named <code>xzfind<\/code> that internally identified itself as <strong>ROOTRUN<\/strong>. The binary used Linux\u2019s <code>setuid<\/code> mechanism to execute attacker-supplied commands with root privileges.<\/p>\n<p><strong>ROOTRUN<\/strong> allowed UTA0533 to execute attacker-supplied commands with root privileges after the initial exploitation.<\/p>\n<p>As long as <strong>ROOTRUN<\/strong> remained installed and accessible, it could provide root-level command execution independently of the Java payloads.<\/p>\n<h3>KNUCKLEBALL<\/h3>\n<p>Instead of creating separate malicious processes, <strong>KNUCKLEBALL<\/strong> injected two Java payloads into an existing SonicWall Java process through the <code>Java Attach API<\/code>. This technique helped the malware blend into normal appliance activity.<\/p>\n<p>UTA0533 added <strong>KNUCKLEBALL<\/strong> to the legitimate appliance startup script, allowing it to:<\/p>\n<ul>\n<li>Run automatically after a reboot.<\/li>\n<li>Reload malicious Java payloads.<\/li>\n<li>Restore malware functionality without re-exploiting the vulnerabilities.<\/li>\n<\/ul>\n<p>The startup-script modification provided <strong>KNUCKLEBALL<\/strong> with reboot persistence, while process injection loaded its Java payloads into a legitimate SonicWall process.<\/p>\n<h3>Suo5<\/h3>\n<p>One <strong>KNUCKLEBALL<\/strong> payload was a modified version of <strong>Suo5<\/strong>, an open-source HTTP proxy tool.<\/p>\n<p><strong>Suo5<\/strong> could allow the compromised SonicWall SMA appliance to relay attacker traffic toward other network resources. Because VPN appliances connect external users with enterprise resources, their compromise may provide a useful proxy point for attempted follow-on activity.<\/p>\n<p>Although <strong>Suo5<\/strong> is publicly available software, its use in this campaign demonstrates how threat actors can combine open-source tools with purpose-built malware.<\/p>\n<h3>ORANGETAIL<\/h3>\n<p>The second Java payload was <strong>ORANGETAIL,<\/strong> a custom web shell that operated similarly to the open-source Behinder <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-web-shell\/\">web shell<\/a>.<\/p>\n<p><strong>ORANGETAIL<\/strong> activated only when requests contained a specific user-agent string; requests that failed validation received an HTTP 404 response.<\/p>\n<p>UTA0533 also modified <code>NGINX Unit<\/code> configurations to:<\/p>\n<ul>\n<li>Expose the <strong>Suo5<\/strong> proxy and <strong>ORANGETAIL<\/strong> web shell through externally accessible routes.<\/li>\n<li>Route external requests through the <code>\/__api__\/login<\/code> and <code>\/__api__\/logout<\/code> URI paths to the injected implants.<\/li>\n<\/ul>\n<p>The modified routes made the <strong>ORANGETAIL<\/strong> command-execution channel and <strong>Suo5<\/strong> HTTP proxy externally reachable.<\/p>\n<h2>How the UTA0533 SonicWall SMA Malware Maintained Access<\/h2>\n<p>UTA0533 modified the appliance environment to preserve specific capabilities after exploitation. Adding <strong>KNUCKLEBALL<\/strong> to a startup script provided reboot persistence, while modified <code>NGINX Unit<\/code> routes exposed the injected implants when they were active.<\/p>\n<p>Observed persistence, access, and stealth techniques included:<\/p>\n<ul>\n<li>Adding <strong>KNUCKLEBALL<\/strong> to a legitimate startup script for reboot persistence.<\/li>\n<li>Injecting Java payloads into a legitimate SonicWall process.<\/li>\n<li>Modifying <code>NGINX Unit<\/code> routes to expose the implants externally.<\/li>\n<li>Installing <strong>ROOTRUN<\/strong> to provide root-level command execution while the utility remained present and accessible.<\/li>\n<\/ul>\n<p>Investigators also found scripts configured to capture unencrypted LDAP traffic on one appliance. This activity appears to indicate preparation to capture unencrypted <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-lightweight-directory-access-protocol-ldap\/\">LDAP<\/a> traffic, potentially including usernames and passwords. However, public reporting has not confirmed that UTA0533 successfully captured credentials.<\/p>\n<p>These findings underline a critical incident-response principle: a patched appliance is not necessarily a clean appliance. Administrators should validate system integrity before returning a previously compromised device to production.<\/p>\n<h2>Indicators of Compromise and Hunting Priorities<\/h2>\n<p>Security teams investigating affected SonicWall SMA appliances should look for:<\/p>\n<ul>\n<li>Unexpected <code>setuid<\/code> binaries, including <strong>ROOTRUN<\/strong>-like utilities.<\/li>\n<li>Modified startup scripts that reload unfamiliar code.<\/li>\n<li>Unauthorized <code>NGINX Unit<\/code> routes or configuration changes.<\/li>\n<li>Evidence that <strong>KNUCKLEBALL<\/strong> used the <code>Java Attach API<\/code> to <code>load \/tmp\/agent_wp8.jar<\/code> or <code>\/tmp\/agent_wp9.jar<\/code> into the SonicWall <code>workplace.startup.CommandStartup<\/code> process.<\/li>\n<li><strong>Suo5-related<\/strong> files, hashes, injected Java classes or routes identified in Volexity\u2019s published indicators.<\/li>\n<li><strong>ORANGETAIL-related<\/strong> hashes, Java classes, URI routes, request parameters or user-agent activity identified in Volexity\u2019s published indicators.<\/li>\n<li>Requests using the specific fabricated user-agent published by Volexity, particularly when directed to unexpected or modified SonicWall SMA routes.<\/li>\n<li>Scripts configured to capture unencrypted LDAP traffic.<\/li>\n<li>Configuration differences from a trusted baseline.<\/li>\n<\/ul>\n<p>Some behavioral findings may not prove compromise independently; however, exact malware hashes, known implant files and confirmed malicious configuration changes can provide strong evidence of compromise. Therefore, defenders should compare them with SonicWall and Volexity indicators, appliance logs and forensic evidence from the relevant exploitation period.<\/p>\n<h2>How UTA0533 Used Appliance-Specific Malware<\/h2>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/07\/sonicwall-sma-zero-days-exploited.html?utm_source=hexnode_blog&amp;utm_medium=referral&amp;utm_campaign=uta0533s_sonicwall_sma_malware\" target=\"_blank\" rel=\"nofollow noreferrer noopener\">UTA0533\u2019s toolkit<\/a> demonstrates how attackers can combine appliance-specific malware, open-source tooling, and configuration changes during post-exploitation. VPN, firewall and other edge appliances can present attractive targets because these systems:<\/p>\n<ul>\n<li>May be directly exposed to the internet.<\/li>\n<li>Occupy trusted network positions.<\/li>\n<li>Provide paths toward internal resources.<\/li>\n<li>May provide less endpoint-style telemetry than fully monitored workstations and servers, depending on the appliance and logging configuration.<\/li>\n<\/ul>\n<p>As a result, organizations should investigate compromised appliances with the same rigor applied to workstations and servers. Rapid patching remains essential, but defenders must also hunt for persistence, validate configurations and examine adjacent systems for follow-on activity.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck.webp?format=webp\" class=\"resource-box__image\" alt=\"Thumbnail-For-XDR-Intro-Deck\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck.webp?format=webp 1796w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-300x168.webp?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1024x575.webp?format=webp 1024w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-768x431.webp?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-1536x862.webp?format=webp 1536w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Thumbnail-For-XDR-Intro-Deck-178x100.webp?format=webp 178w\" sizes=\"auto, (max-width: 1796px) 100vw, 1796px\" title=\"Thumbnail-For-XDR-Intro-Deck\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Introduction to Hexnode XDR\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Learn how Hexnode XDR helps security teams investigate endpoint activity, hunt threats, and accelerate incident response after suspected compromises.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/introduction-to-hexnode-xdr\/'>\n                            Download the Presentation\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<h2>How Hexnode XDR Can Support Post-Compromise Investigations<\/h2>\n<p>The malicious activity occurred on SonicWall SMA appliances and was therefore outside the direct telemetry <a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> collects from managed Windows and macOS endpoints. However, endpoint telemetry becomes important when attackers attempt to move from a compromised appliance to managed devices.<\/p>\n<p>Hexnode XDR can help security teams investigate supported <a href=\"https:\/\/www.hexnode.com\/uem\/platform\/windows-mdm\/\">Windows<\/a> and <a href=\"https:\/\/www.hexnode.com\/uem\/platform\/macos-device-management\/\">macOS<\/a> endpoints by enabling them to:<\/p>\n<ul>\n<li data-section-id=\"1o4znzy\" data-start=\"1139\" data-end=\"1262\">Run Advanced Investigation Queries to search detailed endpoint telemetry for suspicious activity.<\/li>\n<li data-section-id=\"1dimteh\" data-start=\"1263\" data-end=\"1394\">Investigate endpoint behavior, including processes and other endpoint events, to identify potential indicators of compromise.<\/li>\n<li data-section-id=\"5vo9kx\" data-start=\"1395\" data-end=\"1495\">Isolate affected devices to help contain suspicious endpoint activity during an investigation.<\/li>\n<li data-section-id=\"5eiy0r\" data-start=\"1496\" data-end=\"1631\">Terminate malicious processes using the Kill Process action when security teams determine that endpoint response is required.<\/li>\n<\/ul>\n<p>Hexnode XDR can complement appliance forensics by helping security teams investigate managed Windows and macOS endpoints for evidence of possible follow-on activity.<\/p>\n<p>Security teams can review Hexnode XDR endpoint data alongside appliance, network, and identity evidence to investigate possible follow-on activity and decide whether endpoint containment is necessary.<\/p>\n<h3>Conclusion<\/h3>\n<p>The SonicWall SMA zero-days enabled the initial compromise, while the UTA0533 malware toolkit demonstrates an effort to maintain privileged access and support further activity.<\/p>\n<p><strong>ROOTRUN<\/strong> provided root-level command execution while it remained installed and accessible, <strong>KNUCKLEBALL<\/strong> loaded Java payloads, <strong>Suo5<\/strong> provided an HTTP traffic-proxying capability, and <strong>ORANGETAIL<\/strong> provided covert web shell access. Meanwhile, the startup-script modification enabled reboot persistence, while the <code>NGINX Unit<\/code> changes kept <strong>Suo5<\/strong> and <strong>ORANGETAIL<\/strong> accessible through external routes.<\/p>\n<p>The primary lessons are clear:<\/p>\n<ul>\n<li>Patch affected appliances promptly.<\/li>\n<li>Verify appliance integrity after patching.<\/li>\n<li>Hunt for unauthorized binaries and configuration changes.<\/li>\n<li>Investigate adjacent endpoints for follow-on activity.<\/li>\n<li>Treat internet-facing appliances as potentially high-value assets and prioritize them according to their exposure, privileges, and role in the network.<\/li>\n<\/ul>\n<p>Ultimately, recovery from an appliance compromise requires more than installing an update. Organizations should combine patching, appliance forensics and endpoint investigation to identify remaining persistence and increase confidence that unauthorized access has been removed.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Stay Ahead of Emerging Cyber Threats<\/h5><p>Get expert analysis of zero-day attacks, threat actor campaigns, and practical security guidance.<\/p><a href=\"https:\/\/www.hexnode.com\/xdr\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> Try Hexnode Now<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Introduction The UTA0533 SonicWall SMA malware toolkit shows how attackers extended the impact of the&#8230;<\/p>\n","protected":false},"author":4,"featured_media":863,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[12,13],"class_list":["post-862","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zero-day","category-identity-abuse","product_category-identity-provider","tab_group-vulnerabilities"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>UTA0533 SonicWall SMA Malware Toolkit Explained<\/title>\n<meta name=\"description\" content=\"Explore the UTA0533 SonicWall SMA malware toolkit, including ROOTRUN, KNUCKLEBALL, Suo5, ORANGETAIL, and persistence techniques.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"UTA0533 SonicWall SMA Malware Toolkit Explained\" \/>\n<meta property=\"og:description\" content=\"Explore the UTA0533 SonicWall SMA malware toolkit, including ROOTRUN, KNUCKLEBALL, Suo5, ORANGETAIL, and persistence techniques.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-21T08:30:39+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T05:35:33+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UTA0533-SonicWall-SMA-Malware-Toolkit.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"754\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Nora Blake\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Nora Blake\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/\"},\"author\":{\"name\":\"Nora Blake\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\"},\"headline\":\"Inside UTA0533 SonicWall SMA Malware Toolkit: ROOTRUN, KNUCKLEBALL and ORANGETAIL\",\"datePublished\":\"2026-07-21T08:30:39+00:00\",\"dateModified\":\"2026-08-19T05:35:33+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/\"},\"wordCount\":1491,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/UTA0533-SonicWall-SMA-Malware-Toolkit.jpeg?format=webp\",\"articleSection\":[\"Zero-Day\",\"Identity Abuse\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/\",\"name\":\"UTA0533 SonicWall SMA Malware Toolkit Explained\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/UTA0533-SonicWall-SMA-Malware-Toolkit.jpeg?format=webp\",\"datePublished\":\"2026-07-21T08:30:39+00:00\",\"dateModified\":\"2026-08-19T05:35:33+00:00\",\"description\":\"Explore the UTA0533 SonicWall SMA malware toolkit, including ROOTRUN, KNUCKLEBALL, Suo5, ORANGETAIL, and persistence techniques.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/UTA0533-SonicWall-SMA-Malware-Toolkit.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/UTA0533-SonicWall-SMA-Malware-Toolkit.jpeg?format=webp\",\"width\":1340,\"height\":754,\"caption\":\"UTA0533 SonicWall SMA Malware Toolkit\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/inside-uta0533s-sonicwall-sma-malware-toolkit\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Inside UTA0533 SonicWall SMA Malware Toolkit: ROOTRUN, KNUCKLEBALL and ORANGETAIL\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/0c83856887182474458e211729d39f9d\",\"name\":\"Nora Blake\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g\",\"caption\":\"Nora Blake\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/nora-blake\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"UTA0533 SonicWall SMA Malware Toolkit Explained","description":"Explore the UTA0533 SonicWall SMA malware toolkit, including ROOTRUN, KNUCKLEBALL, Suo5, ORANGETAIL, and persistence techniques.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/","og_locale":"en_US","og_type":"article","og_title":"UTA0533 SonicWall SMA Malware Toolkit Explained","og_description":"Explore the UTA0533 SonicWall SMA malware toolkit, including ROOTRUN, KNUCKLEBALL, Suo5, ORANGETAIL, and persistence techniques.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-07-21T08:30:39+00:00","article_modified_time":"2026-08-19T05:35:33+00:00","og_image":[{"width":1340,"height":754,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UTA0533-SonicWall-SMA-Malware-Toolkit.jpeg?format=webp","type":"image\/jpeg"}],"author":"Nora Blake","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Nora Blake","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/"},"author":{"name":"Nora Blake","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d"},"headline":"Inside UTA0533 SonicWall SMA Malware Toolkit: ROOTRUN, KNUCKLEBALL and ORANGETAIL","datePublished":"2026-07-21T08:30:39+00:00","dateModified":"2026-08-19T05:35:33+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/"},"wordCount":1491,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UTA0533-SonicWall-SMA-Malware-Toolkit.jpeg?format=webp","articleSection":["Zero-Day","Identity Abuse"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/","url":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/","name":"UTA0533 SonicWall SMA Malware Toolkit Explained","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UTA0533-SonicWall-SMA-Malware-Toolkit.jpeg?format=webp","datePublished":"2026-07-21T08:30:39+00:00","dateModified":"2026-08-19T05:35:33+00:00","description":"Explore the UTA0533 SonicWall SMA malware toolkit, including ROOTRUN, KNUCKLEBALL, Suo5, ORANGETAIL, and persistence techniques.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UTA0533-SonicWall-SMA-Malware-Toolkit.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/UTA0533-SonicWall-SMA-Malware-Toolkit.jpeg?format=webp","width":1340,"height":754,"caption":"UTA0533 SonicWall SMA Malware Toolkit"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/inside-uta0533s-sonicwall-sma-malware-toolkit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Inside UTA0533 SonicWall SMA Malware Toolkit: ROOTRUN, KNUCKLEBALL and ORANGETAIL"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/0c83856887182474458e211729d39f9d","name":"Nora Blake","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a3937eeab99c0b56fb02ea93c3ccf9d03e2a8056395f0c69ce21777a1907569c?s=96&d=mm&r=g","caption":"Nora Blake"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/nora-blake\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/862","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=862"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/862\/revisions"}],"predecessor-version":[{"id":868,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/862\/revisions\/868"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/863"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=862"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=862"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}