HackMyIP
← Back to News
2026-08-03 The Hacker News

INC Ransomware Dominates SonicWall SMA 1000 Zero-Day Exploitation

RansomwareZero-DayVulnerability

The INC Ransomware operation has rapidly become the "dominant threat actor" weaponizing recently disclosed flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. According to Resecurity, INC Ransomware accelerated its campaign at the start of August 2026, claiming multiple victims on its data leak site and bringing its total tally to 885 organizations, per Ransomware.Live statistics. The group has reportedly chained CVE-2026-15409 and CVE-2026-15410 to achieve arbitrary command execution and take full control of unpatched appliances, despite SonicWall releasing fixes in mid-July 2026.

Both vulnerabilities were weaponized as zero-days before disclosure. Rapid7 observed that attackers leveraged the initial foothold to extract high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication seed configurations—a tactic designed to guarantee long-term persistent access and facilitate lateral movement into internal corporate networks. Volexity attributed the pre-disclosure exploitation, which began on June 22, 2026, to a threat cluster tracked as UTA0533, noting the deployment of a Python loader called KNUCKLEBALL that launches Suo5, an open-source HTTP proxy, alongside ORANGETAIL, a Behinder-style custom Java web shell. "A single threat actor or coordinated group is responsible for discovering and exploiting this zero-day vulnerability," said Douglas McKee, director of vulnerability intelligence at Rapid7, confirming strong tactical overlap with Volexity's findings.

New INC Ransomware victims listed between July 17 and August 1, 2026, span private sector firms and government agencies across Australia, the United States, the UAE, Colombia, and Switzerland. Resecurity also disclosed that many of these victims received unsolicited emails and phone calls from individuals posing as security negotiators, including someone using the name "Andrew" and the number +1 (304) 384-0401, who directed them to negotiate at info@helprans[.]com—classic pressure tactics. Organizations running exposed SonicWall SMA 1000 appliances should apply patches immediately, audit privileged accounts, and rotate any credentials or MFA seeds that may have been harvested. Defenders can also use the port scanner to identify exposed VPN endpoints, run the password checker to evaluate the strength of administrative credentials, and verify any suspicious outreach with the email breach checker before engaging with unknown parties.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →