INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
thehackernews.com Aug 3, 2026

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

AI-summarised brief · reviewed before publication

The INC Ransomware group has become the primary threat exploiting SonicWall SMA 1000 VPN appliances’ flaws CVE‑2026‑15409 and CVE‑2026‑15410. Resecurity’s weekend report notes a surge in activity since early August 2026, with the gang claiming 885 victims, the latest on August 2. The vulnerabilities, patched by SonicWall in mid‑July, were weaponized as zero‑days to run arbitrary commands, steal high‑value credentials, session databases, and TOTP MFA seeds, enabling persistent access and lateral movement. Rapid7 links the campaign to a Python script (KNUCKLEBALL), an open‑source proxy (Suo5), and a custom Java web shell (ORANGETAIL), suggesting a single coordinated actor. Victims span private and government sectors across multiple continents, and many report deceptive “help” calls from a person named “Andrew” offering negotiations via info@helprans[.]com. Resecurity urges immediate patching, credential rotation, and thorough threat hunting.

💡 Why It Matters

  • · The attack demonstrates how quickly unpatched VPN flaws can be turned into a global ransomware supply chain, forcing organizations to reassess patch‑management and incident‑response readiness.