Connect with us

Security

Ransomware Reign: SonicWall SMA 1000 Vulnerabilities Exploited by INC

Published

on

The hacking group known as INC Ransomware is taking advantage of recently revealed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN devices, making them the primary threat actor in this scenario.

According to a recent report by Resecurity, INC Ransomware has been ramping up its attacks since the start of August 2026, with multiple victims already identified on their data leak portal. As reported on Ransomware.Live, the group has claimed a total of 885 victims so far, with the latest attack occurring on August 2, 2026.

The attacks are believed to exploit the CVE-2026-15409 and CVE-2026-15410 vulnerabilities, allowing for arbitrary command execution and the compromise of vulnerable devices. SonicWall had released patches for these vulnerabilities in mid-July 2026.

These vulnerabilities were weaponized as zero-days, with the attackers using them to extract valuable credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication seed configurations. This approach allowed the hackers to maintain long-term access and move laterally within corporate networks.

Volexity, in a subsequent report, linked the exploitation of these vulnerabilities before their public disclosure to a threat group identified as UTA0533. The attacks involved the deployment of a Python script named KNUCKLEBALL, which launched Suo5, an open-source HTTP proxy, and a custom Java web shell called ORANGETAIL.

Rapid7, a cybersecurity firm, confirmed that they had observed similar tactics in their own investigations, indicating that a coordinated group or individual was responsible for discovering and exploiting these vulnerabilities. INC Ransomware has since become the primary threat actor utilizing this vulnerability chain.

Recent victims of INC Ransomware, identified between July 17 and August 1, 2026, include organizations from various countries such as Australia, the U.S., the U.A.E., Colombia, and Switzerland.

See also  Urgent Action Required: CISA Directs Immediate Patching of Dell Vulnerability Under Active Attack

Resecurity also revealed that some of the new victims received emails and phone calls from unknown entities offering to help with ransomware issues. In some cases, victims were contacted by an individual named “Andrew” using the phone number +1 (304) 384-0401.

These unknown entities claimed to be part of a hacking group and informed the victims that their networks had been compromised. At the end of the call, they provided the email address info@helprans[.]com for further communication, using these tactics as pressure tactics commonly employed by ransomware groups.

It is crucial for customers to update their SMA 1000 appliances to the latest version to mitigate these vulnerabilities. Resecurity also recommends conducting thorough threat hunting, rotating credentials, verifying integrity, and patching systems to protect against such threats.

Additionally, Resecurity advises identifying external source addresses interacting with /wsproxy or using unusual parameters and correlating them with internal authentication and lateral movement activities.

Trending