Ethical Hacking News
The recent emergence of the INC Ransomware operation as a dominant threat actor has sent shockwaves throughout the cybersecurity community. The group has accelerated its activity since mid-August 2026, listing multiple victims on its data leak site and claiming over 885 victims to date. To protect themselves against this threat, organizations must patch their SMA 1000 appliances immediately and implement comprehensive security protocols.
The INC Ransomware operation has accelerated its activity since August 2026, claiming 885 victims. The group is exploiting vulnerabilities CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA 1000 series VPN appliances. The attackers are using a sophisticated approach to gain unauthorized access to targeted networks, including extracting high-value credentials and MFA seed configurations. The attacks involve the deployment of custom tools such as KNUCKLEBALL and ORANGETAIL. Organizations are advised to patch SMA 1000 appliances immediately and implement comprehensive security measures, including threat hunting and credential rotation.
The recent emergence of the INC Ransomware operation as a dominant threat actor exploiting the security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances has sent shockwaves throughout the cybersecurity community. According to a report published by Resecurity, the group has accelerated its activity since the beginning of August 2026, listing multiple victims on its data leak site. The statistics listed on Ransomware.Live indicate that the group has claimed 885 victims to date, with the most recent victim listed on August 2, 2026.
The attacks are suspected to involve the exploitation of two vulnerabilities: CVE-2026-15409 and CVE-2026-15410. These vulnerabilities could be chained to facilitate arbitrary command execution and take over susceptible devices. The fixes for the vulnerability pair were released by SonicWall in mid-July 2026, but it appears that the threat actors have weaponized these zero-days.
Rapid7 has noted that the attacks leveraged the foothold to extract high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication (MFA) seed configurations with an aim to ensure long-term, persistent access and ultimately carry out lateral movement into the internal corporate network. This indicates that the attackers are using a sophisticated approach to gain unauthorized access to targeted networks.
In a follow-up report, Volexity attributed the pre-disclosure exploitation starting June 22, 2026, to a threat cluster it tracks as UTA0533. The attacks involve the deployment of a Python script named KNUCKLEBALL that's used to launch Suo5, an open-source HTTP proxy, and a Behinder-like custom Java web shell dubbed ORANGETAIL.
The recent increase in activity by the INC Ransomware operation is particularly alarming, given its rapid acceleration since mid-August 2026. The group has managed to claim a significant number of victims across various countries, including Australia, the U.S., the U.A.E., Colombia, Switzerland, and others. The fact that many of these victims received emails, as well as phone calls from unknown organizations claiming to assist with ransomware issues, highlights the tactics used by the group to trick potential victims into divulging sensitive information.
The attackers have also been using social engineering tactics, where an individual named "Andrew" would make contact with victims via phone and claim that their network had been compromised. The individual provided the email address info@helprans[.]com for further negotiations, which is a common tactic used by ransomware groups to apply pressure on potential victims.
To safeguard against this threat, customers are advised to immediately patch SMA 1000 appliances to the latest version, if not already. Resecurity has also recommended comprehensive threat hunting, credential rotation, and integrity verification alongside patching to ensure that these organizations remain protected from the ongoing attacks.
In conclusion, the recent emergence of the INC Ransomware operation as a dominant threat actor exploiting the security flaws in SonicWall SMA 1000 series VPN appliances highlights the importance of timely patches and robust cybersecurity measures. As the attack landscape continues to evolve, it is crucial for organizations to stay vigilant and implement comprehensive security protocols to safeguard against emerging threats.
Related Information:
https://www.ethicalhackingnews.com/articles/The-SonicWall-SMA-1000-Flaw-A-Vulnerability-that-has-Given-Rise-to-the-Dominant-Ransomware-Operation-INC-ehn.shtml
https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
https://nvd.nist.gov/vuln/detail/CVE-2026-15409
https://www.cvedetails.com/cve/CVE-2026-15409/
https://nvd.nist.gov/vuln/detail/CVE-2026-15410
https://www.cvedetails.com/cve/CVE-2026-15410/
Published: Mon Aug 3 12:50:00 2026 by llama3.2 3B Q4_K_M