Skip to main content
Emerging ThreatsMalware & Ransomware

INC Ransomware Exploits SonicWall SMA 1000 Flaws in Global Campaign

SonicWall SMA 1000 series appliance in an office setting with network closet door ajar.

885 victims to date, the most recent listed on August 2, 2026 — a tally that underlines the rapid rise of INC Ransomware as the primary exploiter of the SonicWall SMA 1000 vulnerability chain.

INC Ransomware: scale and timing of the activity

Resecurity reported that the INC Ransomware operation has "emerged as the 'dominant threat actor'" exploiting recently disclosed flaws in SonicWall Secure Mobile Access (SMA) 1000 series appliances. Per statistics on Ransomware.Live, the group has claimed 885 victims to date, with the most recent victim entry shown on August 2, 2026. Resecurity said it observed INC accelerating activity since the beginning of August 2026 and noted multiple victims listed on INC's data leak site.

Between July 17 and August 1, 2026, Resecurity documented new victims across private sector and government organizations in Australia, the U.S., the U.A.E., Colombia, Switzerland, and other countries — a geographic spread that accompanies the public disclosures and the appearance of claimed breaches on the group’s leak site.

CVE-2026-15409 and CVE-2026-15410: the exploited flaws and available fixes

The attacks are suspected to involve exploitation of CVE-2026-15409 and CVE-2026-15410, a pair of shortcomings that could be chained to permit arbitrary command execution and takeover of susceptible SMA 1000 devices. SonicWall released fixes for the vulnerability pair in mid‑July 2026.

Security vendor Rapid7 assessed that attackers leveraged the foothold to extract high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication seed configurations. Rapid7 described the goal as ensuring long-term, persistent access to enable lateral movement into internal corporate networks.

Observed tooling and the attribution trail: KNUCKLEBALL, Suo5 and ORANGETAIL

Volexity, in a follow-up report, attributed pre-disclosure exploitation beginning June 22, 2026, to a threat cluster it tracks as UTA0533. The activity involved deployment of a Python script named KNUCKLEBALL that launches Suo5, an open-source HTTP proxy, and a Behinder-like custom Java web shell dubbed ORANGETAIL.

Rapid7 told The Hacker News that its own investigations show significant tactical overlaps with the campaign, and Douglas McKee, director of vulnerability intelligence at Rapid7, said the "strong technical correlation indicates that a single threat actor or coordinated group is responsible for discovering and exploiting this zero-day vulnerability." McKee added that "More recently, INC Ransomware has emerged as the dominant threat actor actively weaponizing this vulnerability chain."

Resecurity’s observations on post-compromise behavior and extortion tactics

Resecurity reported that many of the new victims received emails and phone calls from unknown organizations claiming to assist with ransomware issues. In several cases, victims were contacted by an individual using the name "Andrew" and the phone number +1 (304) 384-0401. According to Resecurity, the caller "claimed to be calling 'from a group of hackers' and stated that the victim's network had been compromised." The call ended with the caller providing the email address info@helprans[.]com for further negotiations before hanging up.

Resecurity characterized these direct contacts as "pressure tactics" frequently used by ransomware groups. The company’s timeline of victim listings, combined with these outreach methods, paints a picture of operators combining technical exploitation with social pressure to increase the chances of payment or expedited negotiations.

How customers, security teams, and affected governments should respond, per Resecurity

  • Customers are advised to immediately patch SMA 1000 appliances to the latest version, if not already.
  • Resecurity recommended comprehensive threat hunting, credential rotation, and integrity verification alongside patching to protect against the threat.
  • Specifically, organizations should "identify external source addresses that interacted with /wsproxy or used unusual parameters, and correlate with internal authentication and lateral-movement activity," Resecurity wrote.

Fixes were released by SonicWall in mid‑July 2026, yet public claims and observed exploitation continued into late July and early August. Volexity’s attribution of pre‑disclosure activity to UTA0533 and Rapid7’s assessment that the chain was weaponized as zero-days together outline a timeline in which discovery, exploitation, and public disclosure overlapped.

For now, the immediate, concrete steps on the table are those Resecurity set out: apply the mid‑July patches, hunt for indicators tied to /wsproxy use and unusual parameters, rotate credentials and MFA seeds if compromised, and verify system integrity. At the same time, the INC Ransomware group’s persistent leak listings and reported pressure-calling tactics underscore that remediation will need to combine technical fixes with active incident response and communications discipline.

Original story at The Hacker News