HomeSecurityINC Ransomware emerges as a dominant threat actor

INC Ransomware emerges as a dominant threat actor

The INC Ransomware operation has emerged as the “dominant threat actor” exploiting recently disclosed security vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000.

See also: Marquis: Ransomware attack started with SonicWall cloud backup hack

Article Image: INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
INC Ransomware emerges as a dominant threat actor

In a report published over the weekend, Resecurity said it had observed an acceleration in INC Ransomware activity since early August 2026, recording multiple victims on its data leak website. According to statistics reported on Ransomware.Live, the group has claimed 885 victims to date, with the most recent victim reported on August 2, 2026.

The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be combined to facilitate arbitrary command execution and takeover of vulnerable devices. Patches for the pair of vulnerabilities were released by SonicWall in mid-July 2026.

The two vulnerabilities are assessed to have been exploited as zero-days, with Rapid7 noting that the attacks used the lead to extract high-value credentials, active session databases, and time-based multi-factor authentication (MFA) seed configurations with the goal of securing long-term, persistent access and ultimately performing lateral movement into the internal corporate network.

In a subsequent report, Volexity attributed the pre-disclosure exploit, which began on June 22, 2026, to a threat cluster it tracks as UTA0533. The attacks include the deployment of a Python script called KNUCKLEBALL used to launch Suo5, an open-source HTTP proxy, and a custom Java web shell called Behinder called ORANGETAIL. Rapid7 subsequently told The Hacker News that the campaign shares significant tactical similarities with its own research.

See also: SonicWall: The “incomplete patching” trap that leaves the door open to attacks

INC Ransomware emerges as a dominant threat actor
INC Ransomware emerges as a dominant threat actor

This strong technical correlation suggests that a single threat actor or a coordinated group is responsible for discovering and exploiting this zero-day vulnerability,” said Douglas McKee, director of vulnerability intelligence at Rapid7. “More recently, INC Ransomware has emerged as the dominant threat actor actively utilizing this vulnerability chain.”

Resecurity reported that new victims recorded on the INC Ransomware website between July 17 and August 1, 2026 include private and government organizations from Australia, the U.S., the U.A.E., Colombia, Switzerland, and other countries.

The cybersecurity firm also revealed that many of the new victims received emails and phone calls from unknown organizations claiming to help with ransomware issues. In some cases, victims reportedly contacted an individual using the name “Andrew” using the phone number +1 (304) 384-0401.

He claimed to be calling ‘from a group of hackers’ and stated that the victim’s network had been compromised,” the company noted. “At the end of the call, the individual provided the email address info@helprans[.]com for further negotiations and then ended the call. Such methods are often used by ransomware groups as ‘pressure tactics.’”

Customers are advised to immediately update their SMA 1000 devices to the latest version if they have not already done so. Resecurity has also recommended comprehensive threat hunting, credential change, and integrity verification alongside the threat protection update.

See also: SonicWall SMA: Zero-Days exploited before they were revealed

INC Ransomware - SecNews.gr

"Identify external source addresses that interacted with /wsproxy or used unusual parameters and correlate with internal authentication and lateral movement activity," he added.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS