CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

INC Ransomware Exploits SonicWall SMA 1000 Zero-Days in Widespread Attacks

August 3, 2026

INC Ransomware has emerged as the dominant threat actor exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. According to a report by Resecurity, the group has accelerated its activity since early August 2026, listing numerous victims on its data leak site. Ransomware.Live statistics show the group has claimed 885 victims to date, with the most recent listed on August 2, 2026.

The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which can be chained to achieve arbitrary command execution and take over vulnerable devices. SonicWall released patches in mid-July 2026. Rapid7 noted that the vulnerabilities were weaponized as zero-days, allowing attackers to extract high-value credentials, active session databases, and TOTP MFA seed configurations to maintain persistent access and perform lateral movement.

Volexity attributed pre-disclosure exploitation starting June 22, 2026, to a threat cluster tracked as UTA0533. The attacks deploy a Python script named KNUCKLEBALL, which launches Suo5 (an open-source HTTP proxy) and a Behinder-like custom Java web shell dubbed ORANGETAIL. Rapid7 confirmed significant tactical overlaps with its own investigations, indicating a single threat actor or coordinated group is responsible.

Resecurity reported that new victims between July 17 and August 1, 2026, include private sector and government organizations from Australia, the U.S., the U.A.E., Colombia, Switzerland, and other countries. The company also revealed that many victims received unsolicited emails and phone calls from unknown organizations claiming to assist with ransomware issues. One caller, identifying as “Andrew” from +1 (304) 384-0401, claimed to be from a group of hackers and provided the email info@helprans[.]com for negotiations—a common pressure tactic.

Customers are urged to patch SMA 1000 appliances immediately. Resecurity recommends comprehensive threat hunting, credential rotation, and integrity verification. Organizations should identify external source addresses that interacted with /wsproxy or used unusual parameters and correlate with internal authentication and lateral-movement activity.

CVEs: CVE-2026-15409, CVE-2026-15410, CVE-2026-50522

Attack groups: INC Ransomware, UTA0533

Malware: KNUCKLEBALL, Suo5, ORANGETAIL

Companies: SonicWall, Resecurity, Rapid7, Volexity

Products: SonicWall SMA 1000