INC Ransomware Leverages SonicWall Zero-Days in Global Attack Spree
The **INC Ransomware** operation has escalated its activities, becoming the primary threat actor exploiting recently disclosed zero-day vulnerabilities in **SonicWall Secure Mobile Access (SMA) 1000** series VPN appliances. This aggressive campaign has led to a significant increase in victims across various sectors and geographies, with attackers employing sophisticated tactics for persistence and lateral movement.

Cybersecurity firm **Resecurity** recently reported a significant acceleration in **INC Ransomware** activity since early August 2026. The group has listed numerous new victims on its data leak site, with **Ransomware.Live** statistics indicating 885 claimed victims to date, the most recent on August 2, 2026.
### Exploiting Critical SonicWall Vulnerabilities
The attacks are suspected to involve the exploitation of **CVE-2026-15409** and **CVE-2026-15410**. These vulnerabilities, when chained, allow for arbitrary command execution and complete takeover of susceptible **SonicWall SMA 1000** devices. **SonicWall** released fixes for these critical flaws in mid-July 2026.
These two shortcomings are believed to have been weaponized as zero-days. **Rapid7** noted that initial attacks leveraged these vulnerabilities to extract high-value credentials, active session databases, and **Time-Based One-Time Password (TOTP)** multi-factor authentication (MFA) seed configurations. This level of access ensures long-term persistence and facilitates lateral movement within corporate networks.

### Pre-Disclosure Exploitation and Attacker Attribution
A follow-up report by **Volexity** attributed pre-disclosure exploitation, beginning June 22, 2026, to a threat cluster it tracks as **UTA0533**. These attacks involved the deployment of a Python script named **KNUCKLEBALL**, used to launch **Suo5**, an open-source HTTP proxy, and **ORANGETAIL**, a custom Java web shell similar to Behinder.
**Rapid7** has confirmed significant tactical overlaps with its own investigations, suggesting a single threat actor or a coordinated group is responsible for discovering and exploiting this zero-day vulnerability. Douglas McKee, director of vulnerability intelligence at Rapid7, stated, "More recently, **INC Ransomware** has emerged as the dominant threat actor actively weaponizing this vulnerability chain."
### Global Impact and Pressure Tactics
**Resecurity** highlighted that new victims listed by **INC Ransomware** between July 17 and August 1, 2026, include private sector and government organizations across Australia, the U.S., the U.A.E., Colombia, Switzerland, and other nations.
Adding a layer of psychological warfare, many victims reported receiving emails and phone calls from unknown organizations offering to assist with ransomware issues. In some instances, an individual identifying as "Andrew" contacted victims, claiming to be from a "group of hackers" and providing an email address (**info@helprans[.]com**) for negotiations. These are classic pressure tactics employed by ransomware groups.

### Recommendations for Defense
Organizations using **SonicWall SMA 1000** appliances are strongly advised to immediately patch their systems to the latest available version. Beyond patching, **Resecurity** recommends comprehensive threat hunting, credential rotation, and integrity verification to safeguard against persistent threats.
Security teams should "Identify external source addresses that interacted with /wsproxy or used unusual parameters, and correlate with internal authentication and lateral-movement activity," the company added. This proactive approach is crucial for detecting and mitigating potential breaches.