SonicWall and Unnamed Organizations: INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

SonicWall and Unnamed Organizations: INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

INC Ransomware Exploits Zero-Day Flaws in SonicWall SMA 1000 VPN Appliances

The INC Ransomware group has become the primary threat actor exploiting recently disclosed vulnerabilities in SonicWall’s Secure Mobile Access (SMA) 1000 series VPN appliances. According to a report by Resecurity, the group has intensified its attacks since early August 2026, listing 885 victims on its data leak site as of August 2, 2026.

The attacks leverage two zero-day flaws CVE-2026-15409 and CVE-2026-15410 which were chained to execute arbitrary commands and compromise vulnerable devices. SonicWall released patches for these vulnerabilities in mid-July 2026, but pre-disclosure exploitation began as early as June 22, 2026, attributed to a threat cluster tracked as UTA0533 by Volexity.

The campaign involves deploying a Python script (KNUCKLEBALL) to launch Suo5, an open-source HTTP proxy, and a custom Java web shell (ORANGETAIL). Attackers used the initial access to extract credentials, active session databases, and TOTP multi-factor authentication (MFA) seeds, enabling persistent access and lateral movement within corporate networks.

Rapid7 confirmed significant tactical overlaps in the attacks, suggesting a single threat actor or coordinated group was behind the zero-day exploitation. Since mid-July, INC Ransomware has targeted organizations across Australia, the U.S., the U.A.E., Colombia, Switzerland, and other countries, including both private and government entities.

Resecurity also reported that victims received unsolicited calls and emails from unknown entities claiming to assist with ransomware incidents. Some were contacted by an individual identifying as "Andrew" at +1 (304) 384-0401, directing them to info@helprans[.]com for negotiations a tactic used to pressure victims into paying ransoms.

SonicWall has urged customers to patch affected SMA 1000 appliances immediately, while security firms recommend additional measures such as threat hunting, credential rotation, and integrity verification to mitigate risks.

Source: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html

SonicWall TPRM report: https://www.rankiteo.com/company/sonicwall

Unnamed Organizations TPRM report: https://www.rankiteo.com/company/resecurity

"id": "resson1785832464",
"linkid": "resecurity, sonicwall",
"type": "Ransomware",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'location': ['Australia',
                                     'U.S.',
                                     'U.A.E.',
                                     'Colombia',
                                     'Switzerland'],
                        'type': ['Private organizations',
                                 'Government entities']}],
 'attack_vector': 'Zero-day vulnerabilities in VPN appliances',
 'customer_advisories': 'Victims reported unsolicited calls/emails from '
                        "unknown entities (e.g., 'Andrew' at +1 (304) "
                        '384-0401, info@helprans[.]com).',
 'data_breach': {'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (PII, authentication data)',
                 'type_of_data_compromised': ['Credentials',
                                              'Active session databases',
                                              'TOTP MFA seeds']},
 'date_detected': '2026-06-22',
 'date_publicly_disclosed': '2026-08-02',
 'description': 'The INC Ransomware group has exploited recently disclosed '
                'vulnerabilities in SonicWall’s Secure Mobile Access (SMA) '
                '1000 series VPN appliances. The attacks leverage two zero-day '
                'flaws (CVE-2026-15409 and CVE-2026-15410) to execute '
                'arbitrary commands and compromise vulnerable devices. The '
                'campaign involves deploying a Python script (KNUCKLEBALL) to '
                'launch Suo5 and a custom Java web shell (ORANGETAIL), '
                'enabling credential extraction, persistent access, and '
                'lateral movement within corporate networks. Victims span '
                'multiple countries, including private and government '
                'entities.',
 'impact': {'data_compromised': 'Credentials, active session databases, TOTP '
                                'MFA seeds',
            'identity_theft_risk': 'High (PII exposure)',
            'operational_impact': 'Lateral movement within corporate networks, '
                                  'persistent access',
            'systems_affected': 'SonicWall SMA 1000 series VPN appliances'},
 'initial_access_broker': {'backdoors_established': 'ORANGETAIL (Java web '
                                                    'shell), Suo5 (HTTP proxy)',
                           'entry_point': 'Zero-day vulnerabilities in '
                                          'SonicWall SMA 1000 VPN appliances'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'Zero-day vulnerabilities in VPN appliances can be '
                    'exploited rapidly; timely patching and proactive threat '
                    'hunting are critical.',
 'motivation': 'Financial gain (ransomware extortion)',
 'post_incident_analysis': {'corrective_actions': 'Patch deployment, '
                                                  'credential rotation, threat '
                                                  'hunting, integrity '
                                                  'verification',
                            'root_causes': 'Unpatched zero-day vulnerabilities '
                                           '(CVE-2026-15409, CVE-2026-15410) '
                                           'in SonicWall SMA 1000 appliances'},
 'ransomware': {'data_exfiltration': 'Likely (based on ransomware tactics)',
                'ransomware_strain': 'INC Ransomware'},
 'recommendations': ['Immediately patch SonicWall SMA 1000 appliances',
                     'Rotate credentials and MFA seeds',
                     'Conduct threat hunting for signs of compromise',
                     'Verify system integrity',
                     'Monitor for unsolicited communications related to '
                     'ransomware incidents'],
 'references': [{'date_accessed': '2026-08-02', 'source': 'Resecurity'},
                {'source': 'Volexity'},
                {'source': 'Rapid7'},
                {'source': 'SonicWall'}],
 'response': {'containment_measures': 'Patch deployment (SonicWall), '
                                      'credential rotation, integrity '
                                      'verification',
              'enhanced_monitoring': 'Recommended',
              'remediation_measures': 'Threat hunting, patching vulnerable '
                                      'appliances'},
 'stakeholder_advisories': 'SonicWall has urged customers to patch affected '
                           'appliances immediately.',
 'threat_actor': 'INC Ransomware (UTA0533)',
 'title': 'INC Ransomware Exploits Zero-Day Flaws in SonicWall SMA 1000 VPN '
          'Appliances',
 'type': 'Ransomware',
 'vulnerability_exploited': ['CVE-2026-15409', 'CVE-2026-15410']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.