Skip to content
.ca
sign in

Threat intelligence from Volexity

5 reports on cyfar.ca summarizing Volexity research.

Volexity23 days ago14 minLLM reportcritical

Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation

Volexity discovered threat actor UTA0533 exploiting two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances to achieve root-level remote code execution. CVE-2026-15409 enables pre-auth SSRF via /wsproxy to tunnel to localhost services, while CVE-2026-15410 enables command injection via path traversal in the sysCtrl.execRemoveHotfix endpoint. The actor deployed custom malware including KNUCKLEBALL (Java agent injector), ORANGETAIL (webshell), and ROOTRUN (privilege escalation binary), then used tcpdump to capture LDAP credentials and attempted lateral movement from over 200 IP addresses.

Volexity2 months ago6 minLLM reporthigh

VerdantBamboo: Just Another BRICKSTORM in the Firewall

VerdantBamboo, a Chinese threat actor, compromised edge appliances including Egnyte Storage Sync, pfSense firewalls, and Synology NAS devices to deploy custom malware (BRICKSTORM, PLENET, AGENTPSD). The attackers exploited a compromised MSP and local privilege escalation misconfigurations to maintain long-term persistence, using the compromised devices to proxy traffic and bypass Microsoft 365 Conditional Access policies.

Volexity3 months ago3 minLLM reportlow

Go Get ‘Em: Updates to Volexity Golang Tooling

Volexity has released updates to its Golang reverse engineering tooling to address the growing trend of Go-based malware and obfuscation techniques like Garble. The release introduces GoStringExtractor, a plugin for IDA Pro and Ghidra that organizes unterminated Go string tables, and updates GoResolver to recover runtime type information (RTTI), significantly enhancing static analysis capabilities.

Volexity3 months ago7 minLLM reporthigh

APT Meets GPT: Targeted Operations with Untamed LLMs

The China-aligned threat actor UTA0388 is leveraging Large Language Models (LLMs) to conduct highly tailored, rapport-building spear-phishing campaigns targeting organizations in North America, Asia, and Europe. These campaigns deliver GOVERSHELL, a custom backdoor deployed via DLL search order hijacking, which has undergone rapid, non-iterative development across five variants to evade detection and establish persistent C2.

Volexity3 months ago6 minLLM reporthigh

Dangerous Invitations: Russian Threat Actor Spoofs European Security Events in Targeted Phishing Attacks

Russian threat actor UTA0355 is conducting targeted phishing campaigns against foreign policy and government professionals by spoofing European security conferences. The attackers use rapport-building techniques and out-of-band messaging to trick victims into authorizing malicious Microsoft 365 OAuth applications and Device Code workflows, granting unauthorized access to their accounts.