The recent surge in ransomware attacks has been attributed to vulnerabilities in SonicWall’s SMA1000 secure remote access devices. According to a report by Resecurity, the INC Ransomware group is primarily responsible for exploiting these security flaws.
Details of the SonicWall Vulnerabilities
The identified vulnerabilities, CVE-2026-15409 and CVE-2026-15410, have been given a CVSS score of 10 and 7.2, respectively. These flaws allow attackers to create a WebSocket tunnel into restricted services and escalate privileges to root, posing a significant threat to affected systems.
Patches for these vulnerabilities were released on July 14, coinciding with their inclusion in CISA’s Known Exploited Vulnerabilities catalog. However, evidence suggests that these security gaps were being exploited as zero-day vulnerabilities since at least June 22.
Exploitation Patterns and Threat Actors
Volexity, a cybersecurity firm, has linked the exploitation of these vulnerabilities to a threat actor known as UTA0533. This actor has been involved in credential theft from compromised devices and deploying malicious files, although lateral movement to other systems has been limited.
Another firm, Rapid7, observed attackers using the compromised SMA1000 devices as a launchpad into internal corporate networks, possibly by installing backdoors on the affected appliances.
INC Ransomware Group’s Aggressive Tactics
Resecurity’s findings indicate that the INC Ransomware group is the most active in leveraging these vulnerabilities. Since the beginning of August 2026, there has been an uptick in their operations, with numerous new victims appearing on their Data Leak Site.
Victims have spanned various sectors, including private and government organizations across the US, Australia, UAE, Colombia, and Switzerland. Resecurity has been assisting these victims with digital forensics and incident response to identify and mitigate the root cause of the breaches.
Victims of the ransomware attacks have also been targeted with deceptive communications from actors claiming to offer assistance with ransomware issues. In one instance, these communications originated from a domain registered through a Chinese domain registrar, further complicating the response efforts.
Recommendations for Users
As ransomware groups continue to target the SonicWall vulnerabilities, it is critical for users to promptly apply patches to their SMA1000 devices and engage in proactive threat hunting to detect potential intrusions. Staying informed and vigilant is key to safeguarding against these evolving cyber threats.
