INC Ransomware has emerged as the primary threat actor exploiting recently disclosed security flaws affecting SonicWall Secure Mobile Access SMA 1000 series VPN appliances, according to new research published by cybersecurity firm Resecurity. The report states that the ransomware operation significantly increased its activity at the beginning of August 2026, adding multiple organizations to its data leak site. Statistics published by Ransomware.Live indicate that the group has claimed 885 victims so far, with the latest victim appearing on August 2, 2026. Researchers believe the attacks involve the exploitation of vulnerabilities tracked as CVE 2026 15409 and CVE 2026 15410. When chained together, the flaws can enable arbitrary command execution and allow attackers to fully compromise vulnerable SonicWall SMA 1000 devices. SonicWall released security updates addressing both vulnerabilities in mid July 2026, but researchers believe the flaws had already been exploited before public disclosure.
Security researchers have assessed the vulnerabilities as zero day attacks that were actively weaponized before patches became available. Rapid7 reported that attackers used the compromised VPN appliances to extract valuable credentials, active session databases, and Time Based One Time Password multi factor authentication seed configurations. This information was then used to maintain persistent access to targeted environments and support lateral movement across internal corporate networks. In a separate investigation, Volexity attributed the early exploitation activity, which began on June 22, 2026, to a threat cluster identified as UTA0533. According to the report, attackers deployed a Python based tool known as KNUCKLEBALL to install Suo5, an open source HTTP proxy, along with a custom Java web shell called ORANGETAIL that shares similarities with the Behinder web shell. Rapid7 later stated that its own investigation identified significant technical similarities with Volexity findings, suggesting that a single threat actor or closely coordinated group is responsible for discovering and exploiting the vulnerability chain before public disclosure. Researchers also noted that INC Ransomware has since become the most active group using these vulnerabilities in ongoing attacks.
Resecurity reported that organizations affected between July 17 and August 1, 2026, include both private sector companies and government entities across Australia, the United States, the United Arab Emirates, Colombia, Switzerland, and several other countries. The cybersecurity company also revealed that many victims received emails and telephone calls from individuals claiming to assist with ransomware incidents. In several reported cases, an individual identifying himself as Andrew contacted victims using the phone number +1 304 384 0401, claiming to represent a group of hackers and informing organizations that their networks had been compromised. Victims were then instructed to continue negotiations through the email address info@helprans.com before the caller ended the conversation. Researchers described these communications as pressure tactics commonly used by ransomware groups to increase psychological pressure on victims during extortion attempts. The incidents highlight how ransomware operators continue combining technical attacks with social engineering techniques to increase the likelihood of payment negotiations.
Cybersecurity experts are urging organizations using SonicWall SMA 1000 appliances to immediately install the latest security updates if they have not already done so. Resecurity also recommends performing comprehensive threat hunting activities, rotating credentials, and verifying the integrity of affected systems after applying patches to ensure attackers have not established persistence within the environment. Organizations are advised to review external source addresses that communicated with the wsproxy component or used unusual parameters and correlate those activities with internal authentication records and evidence of lateral movement across the network. Researchers believe that patching alone may not be sufficient if attackers compromised systems before updates were installed. Security teams are therefore encouraged to conduct detailed forensic reviews and monitor authentication activity to identify any remaining signs of compromise related to the SonicWall vulnerability chain.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.