Key Takeaways
- INC Ransomware has become the dominant threat actor exploiting newly disclosed SonicWall Secure Mobile Access (SMA) 1000 series flaws.
- The group is chaining CVE‑2026‑15409 and CVE‑2026‑15410 to achieve arbitrary command execution and persistent network access.
- Attacks began as early‑June zero‑day exploitation (tracked as UTA0533 by Volexity) and involve the Python script KNUCKLEBALL, the open‑source proxy Suo5, and a custom Java web shell ORANGETAIL.
- Victims span private‑sector and government entities across Australia, the U.S., the U.A.E., Colombia, Switzerland, and other nations.
- Ransomware operators employ pressure tactics, including unsolicited calls from an individual named “Andrew” and fraudulent assistance emails.
- Immediate patching of SMA 1000 appliances, credential rotation, comprehensive threat hunting, and integrity verification are essential defenses.
Overview of INC Ransomware Activity
Since early August 2026, INC Ransomware has accelerated its operations, repeatedly appearing on its data‑leak site with new victim listings. According to Ransomware.Live statistics, the group has claimed 885 victims to date, with the most recent entry dated August 2, 2026. This surge coincides with the public disclosure of two critical vulnerabilities in SonicWall’s Secure Mobile Access (SMA) 1000 series VPN appliances, positioning INC as the primary actor leveraging these flaws for extortion campaigns. The rapid uptick in victim announcements underscores the group’s ability to transition from initial compromise to data exfiltration and ransom demands within a short window.
Exploited SonicWall SMA Vulnerabilities
The attacks are suspected to stem from the chaining of CVE‑2026‑15409 and CVE‑2026‑15410, both affecting the SMA 1000 series. When exploited together, these flaws enable arbitrary command execution on the appliance, granting attackers full control over the VPN gateway. SonicWall released patches for the vulnerability pair in mid‑July 2026, but many organizations had not applied the updates before the zero‑day window opened, leaving a sizable attack surface. The nature of the flaws—particularly their impact on authentication and session handling—makes them ideal footholds for establishing persistent presence inside corporate networks.
Weaponization as Zero‑Day and Attack Chain
Rapid7 and Volexity have identified that the vulnerabilities were weaponized as zero‑days prior to public disclosure. By exploiting the chain, threat actors can extract high‑value credentials, active session databases, and Time‑Based One‑Time Password (TOTP) seed configurations used for multi‑factor authentication (MFA). Harvesting TOTP seeds allows attackers to generate valid one‑time codes indefinitely, effectively bypassing MFA protections and ensuring long‑term, stealthy access. This credential harvesting facilitates lateral movement, enabling the ransomware operators to traverse internal networks, locate valuable data, and prepare for encryption and extortion phases.
Tools and Techniques: KNUCKLEBALL, Suo5, and ORANGETAIL
Volexity’s analysis attributed the pre‑disclosure exploitation starting June 22, 2026, to a threat cluster tracked as UTA0533. The campaign deploys a Python script named KNUCKLEBALL, which launches Suo5, an open‑source HTTP proxy used to relay traffic and obscure the origin of malicious commands. Following the proxy, attackers drop a Behinder‑like custom Java web shell dubbed ORANGETAIL. This web shell provides a persistent backdoor for executing arbitrary commands, uploading additional payloads, and maintaining communication with command‑and‑control (C2) infrastructure. The combination of a lightweight proxy and a versatile web shell reflects a mature, modular attack framework designed for reliability and evasion.
Geographic Scope and Victim Profile
Resecurity reported that the new victims listed on INC Ransomware’s site between July 17 and August 1, 2026, include private‑sector and government organizations from a diverse set of countries: Australia, the United States, the United Arab Emirates, Colombia, Switzerland, and others. This geographic spread indicates that the vulnerability is being exploited indiscriminately across regions, with no apparent sectoral preference. Both corporate enterprises and public‑sector agencies appear susceptible, highlighting the broad impact of unpatched SMA appliances on critical infrastructure and business operations worldwide.
Pressure Tactics and Social Engineering Calls
Beyond technical intrusion, INC Ransomware employs psychological pressure to hasten ransom payment. Many victims reported receiving unsolicited emails and phone calls from unknown entities claiming to offer ransomware assistance. In several instances, an individual identifying himself as “Andrew” called from the number +1 (304) 384‑0401, stating that the victim’s network had been compromised and providing the email address info@helprans[.]com for further negotiation. Such calls are characteristic of ransomware groups’ “pressure tactics,” aiming to create urgency, fear, and a perception of helpfulness that drives victims toward negotiation rather than restoration from backups.
Mitigation Recommendations and Ongoing Defense
To counter the ongoing threat, organizations must immediately patch all SonicWall SMA 1000 appliances to the latest firmware version released in mid‑July 2026. Patching alone, however, is insufficient; Resecurity advises comprehensive threat hunting focused on identifying external source addresses that interacted with the /wsproxy endpoint or used anomalous parameters, correlating these with internal authentication logs and lateral‑movement indicators. Credential rotation—especially for privileged accounts and any secrets potentially harvested from session databases—is critical, as is verifying the integrity of TOTP seed stores to ensure they have not been cloned. Implementing multi‑layered monitoring, enforcing least‑privilege access, and maintaining offline, tested backups will further reduce the likelihood of successful ransomware execution and improve resilience against future zero‑day exploits.

