INC ransomware is appearing more and more often in security reports involving VPN appliances. According to Resecurity, the group has grown into one of the most dominant threats, with attacks leveraging recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000.
What makes this especially urgent: the vulnerabilities appear to have been used as a zero-day almost immediately. It also looks like the intrusion is not just about initial access, but primarily about maintaining long-term control—so the attackers can roll out further attacks within the network.
Why INC ransomware targets the SMA 1000 in particular
Resecurity says activity from INC ransomware has increased since the beginning of August 2026. On the group’s data leak site, multiple victims are also listed, including organizations from the private sector and government entities.
In this case, it involves SonicWall SMA 1000 appliances. These devices are used as an entry point for external connections. If attackers know how to abuse such an interface, they can often move on to gathering information and preparing for later lateral movement.
The vulnerability chain: CVE-2026-15409 and CVE-2026-15410
The attacks are linked to two specific vulnerabilities: CVE-2026-15409 and CVE-2026-15410. Resecurity and other researchers assess the combination as a scenario that can be “chained” to ultimately enable arbitrary command execution and take over affected systems.
SonicWall released fixes in mid-July 2026. However, because the attacks point to earlier exploitation, the vulnerability set is viewed as potentially being weaponized into zero-days soon after.
What the attacker tries to achieve first
Rapid7 notes that the campaign shows technical overlap with earlier research by its own organization. The approach focuses not only on getting in, but also on securing material that supports long-term access.
Specifically, it is mentioned that attackers may try to obtain valuable credentials, active session databases, and TOTP-MFA seed configurations via the initial foothold. With such a collection in place, the attacker is more likely to avoid being stopped quickly—even if one layer of defense fails.
From foothold to persistence and lateral movement
In the described attack cycle, it is about more than a single moment of successful exploitation. The chain is used to build persistence and then move laterally toward the internal corporate network.
This pattern fits ransomware campaigns in which the goal is often to first broaden privileges and access, then position data, and ultimately cause the organization to lose on multiple fronts.
UT A0533 and tooling: KNUCKLEBALL, Suo5, and ORANGETAIL
Volexity writes that exploits occurred before publication, starting on June 22, 2026. The company links this early phase to a threat cluster it tracks as UTA0533.
According to Volexity, a Python script named KNUCKLEBALL is used. The script is used to launch Suo5, an open-source HTTP proxy. It also reports a webshell in the style of Behinder: a modified Java webshell called ORANGETAIL.
This kind of tooling highlights one important point for defenders: exploitation is often only the first link. After that comes a sequence of steps in which the attacker tries to organize remote access, communications, and hidden control.
New victims and “pressure” toward organizations
Resecurity reports that INC ransomware posted new victims between July 17 and August 1, 2026. It also lists mentions of countries including Australia, the United States, the UAE, Colombia, Switzerland, and other locations.
Another striking detail described by Resecurity is an additional form of contact: many victims would have received emails as well as phone calls from unknown parties posing as ransomware help. In some cases, a person named Andrew would have contacted from the number +1 (304) 384-0401.
Resecurity says the caller claims to be “from a group of hackers,” that the network has been compromised, and then provides an email address—info@helprans[.]com—to start negotiations. According to Resecurity, tactics like these are often intended as a pressure tactic toward victims.
What organizations should do now
The core message is simple: patch immediately. Customers are advised to update SonicWall SMA 1000 appliances to the latest version if they have not already done so.
Resecurity also emphasizes that patching alone is not enough. The guidance includes additional measures to look for signs of abuse.
Concrete next steps for detection and recovery
- Do threat hunting on suspicious external connections, with special attention to interactions with /wsproxy and requests with abnormal parameters.
- Correlation: link external indicators to internal authentication and lateral movement activities.
- Credential rotation: rotate accounts you suspect have been exposed.
- Verify system integrity of systems and relevant configurations to determine whether persistent changes were made.
- Check MFA: if TOTP seeds or configurations have been compromised, you should re-examine your MFA approach and rebuild it where needed.
By combining these steps, you reduce the chance that an attacker still has access after patching—via stolen sessions, credentials, or MFA-related configurations.
Why this goes beyond one single vendor
Although the news right now focuses on SonicWall SMA 1000 and the rise of INC ransomware, this case mainly shows how attacks on VPN infrastructure work. VPN appliances are often a strategic starting point: they provide access to internal networks and frequently expose connections that serve as a platform for further steps.
That’s why it’s wise to test not only vendor patches, but also your own investigation and response routines—especially when you see attackers combining zero-day chains with credential theft and lateral movement.
Conclusion
INC ransomware is in the spotlight as a threat actively weaponizing vulnerabilities in SonicWall SMA 1000. The focus is on CVE-2026-15409 and CVE-2026-15410, where the chain can lead to command execution and the takeover of devices. Researchers also point to the collection of credentials, session data, and TOTP-MFA seeds to enable long-term access.
If you may have been impacted, it’s important to patch right away, then thoroughly search for suspicious indicators, and subsequently rotate credentials and verify integrity. Only then do you reduce the chance that an attacker strikes again through the same attack paths.
Related: read also Incident response: 73% not ready for a major attack to understand why rapid detection and preparation are crucial for ransomware campaigns like this.
Source: https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
