Skip to main content
Emerging ThreatsMalware & Ransomware

INC Ransomware Exploits SonicWall Zero-Days Amid Rising Attacks

Network equipment racks with a SonicWall device in a well-lit office IT room.

"INC ransomware has emerged as the most commonly named threat actor actively weaponizing this vulnerability chain," Brett Deroche, director of incident response at Rapid7, told CyberScoop.

The SonicWall zero-days: CVE-2026-15409 and CVE-2026-15410

Two SonicWall vulnerabilities — CVE-2026-15409 and CVE-2026-15410 — were actively exploited for roughly three weeks before the vendor disclosed and patched the defects on July 14. Researchers say attackers chained the pair together to achieve full access to targeted devices. SonicWall did not respond to a request for comment about the incidents.

INC ransomware’s role in post-disclosure exploitation

INC ransomware, described by researchers as a prolific ransomware-as-a-service operation and "one of the most active ransomware groups globally," has been the most assertive actor exploiting the SonicWall zero-days since public disclosure. INC is not alleged to have been the first to exploit the flaws; earlier activity began before disclosure. But since the patches were released, INC has been prominent in chaining the two vulnerabilities in rapid attacks that moved from initial access to ransomware deployment in short order.

The group has claimed nearly 900 victims across 71 countries since it was first discovered three years ago, according to the reporting. Resecurity reported that INC’s data leak site listed multiple new alleged victims, including organizations and government agencies in Australia, the United States, the United Arab Emirates, Colombia and Switzerland.

Rapid7 observations: June 22 activity, attribution caveats, and outcomes

Rapid7 traced the earliest exploitation it observed to June 22; those initial attacks "were largely unsuccessful," Brett Deroche said. After public disclosure and patching, Rapid7 observed confirmed INC activity using different infrastructure and a faster operational tempo. Deroche cautioned that "attribution here isn’t a single clean answer" and that while INC is the name driving the post-disclosure wave, the full body of exploitation cannot be attributed solely to that group.

Rapid7 told CyberScoop it successfully prevented data theft and encryption in the majority of recent cases it tracked, but also noted that ransomware was deployed in at least one case. The company also warned that there could be other attacks outside the purview of its telemetry.

SonicWall’s recent security history and continuing pressure

The two zero-days are the latest in a string of security issues affecting SonicWall customers. The vendor’s customers have faced multiple actively exploited zero-days and other disclosed defects; last year an attack allowed a state-sponsored threat group to steal the firewall configurations of every SonicWall customer, the reporting notes. Ten of the 17 SonicWall defects added to the Cybersecurity and Infrastructure Security Agency’s known exploited vulnerabilities (KEV) catalog since late 2021 are known to be used in ransomware campaigns.

Activity has remained intense: "Just last week, Huntress researchers spotted an attack spree that compromised 30 SonicWall customers in less than two days," the reporting said, underscoring a continuing, concentrated interest from ransomware groups in SonicWall infrastructure.

How incident responders, SonicWall customers, and regulators are reacting

  • Incident responders and security vendors: Rapid7 has been actively tracking exploitation, preventing theft and encryption in most observed cases, and distinguishing pre- and post-disclosure operations by differences in infrastructure and speed. Resecurity has provided incident-response assistance to several victims and reported on extortion attempts that included emails and phone calls pressuring victims to negotiate.
  • SonicWall customers and procurement leaders: Organizations using SonicWall appliances face renewed pressure from financially motivated groups—ransomware groups have repeatedly targeted SonicWall—making patching and incident readiness immediate priorities for affected enterprises.
  • Policymakers and regulators: The trend of SonicWall defects appearing in CISA’s KEV catalog, and the known use of many of those defects in ransomware campaigns, keeps the vendor and its customers within CISA’s focus for known exploited vulnerabilities and related mitigations.

Researchers have not yet determined how many organizations were impacted by these particular zero-days, including which attacks are tied to INC ransomware. Attribution remains mixed: earlier June activity traced to common hosted infrastructure largely failed, while confirmed INC operations after disclosure used different infrastructure and a more aggressive pace, Rapid7 reported. That contrast — unsuccessful pre-disclosure probes followed by faster, post-disclosure exploitation by a prolific ransomware-as-a-service operation — is the immediate technical story. The wider operational question left open is how many victims exist beyond those that have been publicly listed or observed by the firms tracking the incidents.

Read the original CyberScoop story