Executive Summary
Two critical zero-day vulnerabilities in SonicWall SMA 1000 Series appliances—CVE-2024-1709 (Server-Side Request Forgery, CVSS 10.0) and CVE-2024-1708 (Local Privilege Escalation, CVSS 8.8)—have been actively exploited in the wild since at least April 2024. Attackers are chaining these flaws to achieve unauthenticated remote code execution and escalate privileges to root, enabling full compromise of affected appliances and facilitating lateral movement into internal networks. The exploitation campaign was observed weeks before public disclosure and patch release, with evidence of credential theft, session hijacking, and multi-factor authentication (MFA) seed extraction. Organizations using vulnerable SonicWall SMA 1000 Series appliances are at immediate risk and must take urgent action to patch, investigate, and remediate.
Threat Actor Profile
The threat actors exploiting these vulnerabilities have not been definitively attributed to a specific Advanced Persistent Threat (APT) group. However, their tactics, techniques, and procedures (TTPs) demonstrate a high level of sophistication and operational security. The attackers leverage commercial VPN infrastructure, notably from FNS Holdings Limited (ASN 206092), to obfuscate their origin and evade detection. Asset names such as DESKTOP-KRLUI3J, DESKTOP-IC3C80F, DESKTOP-5P0TSCP, KALI, and localhost have been observed in connection with malicious activity. The campaign is characterized by rapid exploitation, credential harvesting, and the deployment of custom tooling for persistence and lateral movement. The use of open-source and custom malware, as well as the targeting of authentication mechanisms, suggests a well-resourced and technically adept adversary.
Technical Analysis of Malware/TTPs
The attack chain begins with exploitation of CVE-2024-1709, a critical SSRF vulnerability in the /wsproxy endpoint of the SonicWall SMA 1000 Series. This flaw allows unauthenticated attackers to establish websocket tunnels to arbitrary localhost-only services, such as the Erlang process on TCP port 1050 and the ctrl-service on TCP port 8188. By leveraging this access, attackers can interact with internal services that are not exposed externally.
Once internal access is achieved, the attackers exploit CVE-2024-1708, a local privilege escalation vulnerability in the remove_hotfix workflow. This flaw is triggered by sending a crafted request containing a path traversal payload to the rollbackConfirm.action endpoint, referencing a malicious script on the filesystem. If the script exists, it is executed as root, granting the attacker full control over the appliance.
The attackers have been observed deploying a range of tools and malware, including:
- ROOTRUN: A privilege escalation utility, often deployed as a binary named xzfind.
- KNUCKLEBALL: A Python-based loader, typically named deploy_new.py, used to execute additional payloads.
- Suo5: An open-source proxy tool, observed as agent_wp8.jar, facilitating command and control (C2) communications.
- ORANGETAIL: A custom web shell, deployed as agent_wp9.jar, providing persistent remote access.
The attackers also extract sensitive artifacts, including credential databases, session tokens, and TOTP MFA seeds, enabling them to bypass authentication controls and move laterally within the victim environment. MITRE ATT&CK techniques observed include T1190 (Exploit Public-Facing Application), T1211 (Exploitation for Privilege Escalation), T1078 (Valid Accounts), T1021 (Remote Services), and T1556 (Modify Authentication Process).
Exploitation in the Wild
Active exploitation of these vulnerabilities has been confirmed by multiple sources, including Rapid7, HelpNetSecurity, and TheHackerNews. The campaign began in early April 2024, with attackers leveraging the SSRF vulnerability to access internal services and chaining it with the privilege escalation flaw for root-level code execution. The exploitation was widespread and targeted, with evidence of credential theft, session hijacking, and the extraction of MFA seeds.
Indicators of compromise (IOCs) associated with this campaign include:
- IP addresses from FNS Holdings Limited: 45.131.194.0/24, 45.146.54.0/24, 63.135.161.0/24, 173.239.211.0/24, 193.37.32.179, 193.37.32.214, 216.73.163.151, 216.73.163.158.
- Attacker asset names: DESKTOP-KRLUI3J, DESKTOP-IC3C80F, DESKTOP-5P0TSCP, KALI, localhost.
- Log patterns: extraweb_access.log entries with "GET" and "wsproxy" and "=-3389" and "101", suspicious host parameters such as "localhost" or "::ffff:127.0.0.1".
- ctrl-service.log entries showing /usr/local/bin/remove_hotfix invoked with traversal payloads (e.g., "../../../../../../tmp/sma1000_5c47.sh").
- Repeated requests to /auth1.html, path traversal attempts, and file enumeration.
- NTLM logons (Windows Event ID 4624, logon type 3) from appliance IPs with non-corporate workstation names.
- Artifacts such as /var/lib/unit/conf.json with unauthorized routes for /api/login or /api/logout, and access to /tmp/temp.db* (session data theft).
Proof-of-concept (PoC) exploit code for CVE-2024-1709 is publicly available, and a Metasploit module for the full attack chain is reportedly in development.
Victimology and Targeting
The exploitation campaign has primarily targeted organizations deploying vulnerable SonicWall SMA 1000 Series appliances, including models 6210, 7210, and 8200v running affected firmware versions (12.4.3-02999, 12.4.3-03043, 12.4.3-03099, 12.5.0-02165, 12.5.0-02238, 12.5.0-02283). The attacks are opportunistic but have also demonstrated a degree of selectivity, with a focus on enterprises and critical infrastructure sectors that rely on SonicWall for secure remote access.
Victims have experienced full appliance compromise, credential and session theft, and subsequent lateral movement into internal networks. Attackers have been observed authenticating to Active Directory and other internal services using harvested credentials, often bypassing VPN tunnels and traditional perimeter defenses. The theft of TOTP MFA seeds further undermines authentication security, enabling persistent access even after password resets.
Mitigation and Countermeasures
Immediate action is required to mitigate the risk posed by these vulnerabilities. Organizations should:
Patch all affected SonicWall SMA 1000 Series appliances by upgrading to firmware version 12.4.3-03100 or 12.5.0-02284 (platform-hotfix) or later. There are no effective workarounds short of patching and comprehensive incident response.
If compromise is suspected, conduct a forensic review of logs for the IOCs listed above, re-image physical appliances or redeploy virtual appliances, change all user and administrator passwords, reset all TOTP tokens, and review internal authentication logs for anomalous activity. It is critical to assume that credentials and MFA seeds may have been compromised and to take appropriate steps to re-secure all affected accounts and systems.
Organizations should also monitor for the presence of attacker tools and artifacts, such as unexpected binaries in /var/tmp or /tmp, unauthorized modifications to /var/lib/unit/conf.json, and anomalous network connections to known attacker IP ranges.
References
- Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero-Days Being Actively Exploited (CVE-2024-1709, CVE-2024-1708)
- HelpNetSecurity: SonicWall SMA zero-days exploited
- TheHackerNews: SonicWall SMA Zero-Days Exploited
- SonicWall Security Advisory
- CISA KEV Catalog
- NVD: CVE-2024-1709
- NVD: CVE-2024-1708
About Rescana
Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to continuously monitor, assess, and mitigate cyber risks across their extended supply chain. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify vulnerabilities, respond to emerging threats, and ensure compliance with industry standards. For more information about how Rescana can help strengthen your organization's cyber resilience, or for any questions regarding this advisory, please contact us at info@rescana.com.



