The INC Ransomware group has positioned itself as a leading threat by exploiting vulnerabilities in SonicWall’s Secure Mobile Access (SMA) 1000 series VPN appliances. This development follows the identification of significant security flaws, prompting urgent attention from cybersecurity experts worldwide.
Escalation of Ransomware Attacks
In a recent analysis by Resecurity, INC Ransomware activities have surged since early August 2026, with multiple entities listed on their data leak site. According to Ransomware.Live, the group has so far claimed 885 victims, with the latest attack reported on August 2, 2026. The exploitation primarily targets vulnerabilities identified as CVE-2026-15409 and CVE-2026-15410, which allow attackers to execute arbitrary commands and compromise vulnerable systems. SonicWall released patches for these issues in mid-July 2026.
Technical Exploitation and Tactics
The vulnerabilities have been reportedly used as zero-day exploits. Rapid7 has observed that attackers utilized these flaws to obtain crucial credentials, access active session databases, and manipulate Time-Based One-Time Password (TOTP) MFA configurations. These actions aim to secure persistent access and enable lateral movement within corporate networks. Volexity’s follow-up investigation unveiled pre-disclosure exploitation activities traced to a threat cluster known as UTA0533, which used a Python script, KNUCKLEBALL, to deploy tools such as Suo5 and a customized Java web shell named ORANGETAIL.
Rapid7’s research aligns with these findings, indicating potential coordination among threat actors who first discovered and exploited this zero-day vulnerability. Douglas McKee of Rapid7 emphasized the technical alignment, suggesting a singular or collective effort in capitalizing on these flaws.
Impact on Global Organizations
Between July 17 and August 1, 2026, INC Ransomware listed new victims, including private and government sectors from countries like Australia, the United States, the UAE, Colombia, and Switzerland. Resecurity reported that affected organizations received communications from unknown entities offering ransomware assistance, sometimes involving a caller named “Andrew,” using a specific phone number, and providing an email for further contact. These tactics are common pressure strategies employed by ransomware operators.
Preventative Measures and Recommendations
Experts advise organizations to quickly update their SMA 1000 appliances to the newest software version. Alongside patching, Resecurity recommends thorough threat hunting, credential updates, and integrity checks to mitigate the risks associated with these vulnerabilities. It is also advised to monitor external interactions with critical network parameters and correlate these with internal authentication activities to detect unusual patterns and prevent lateral movements.
As cyber threats evolve, maintaining robust cybersecurity measures and staying informed about potential vulnerabilities remain crucial for safeguarding organizational networks.
