INC ransomware cashes in on SonicWall SMA1000 zero-day chain

The INC ransomware gang is the most active user of two exploited SonicWall SMA1000 flaws, adding victims across five countries to its leak site.

CSBadmin
2 Min Read

The INC Ransomware group is behind most recent activity exploiting two fresh vulnerabilities in SonicWall’s SMA1000 secure remote access appliances, according to Resecurity.

Tracked as CVE-2026-15409, a flaw scored a perfect 10, and CVE-2026-15410, scored 7.2, the defects let unauthenticated remote attackers open a WebSocket tunnel to restricted services and escalate privileges to root. SonicWall patched them on July 14, and CISA added both to its Known Exploited Vulnerabilities catalog the same day. The bugs had been exploited as zero-days since at least June 22.

Volexity attributed earlier exploitation to an actor tracked as UTA0533, which harvested credentials and dropped malicious files. Rapid7 observed attackers pivoting from compromised SMA1000 devices into internal corporate networks, likely after deploying a backdoor.

Resecurity says INC Ransomware has accelerated: since the start of August, its data leak site has listed new victims in the US, Australia, UAE, Colombia and Switzerland. The firm has helped several victims with incident response and vulnerability assessments.

Resecurity also flagged pressure tactics: victims received emails from unknown organizations claiming to help with ransomware issues, one from a domain registered after the exploitation activity through a Chinese registrar, plus phone calls from someone calling themselves Andrew who offered an email address for negotiations.

Users should patch SMA1000 appliances immediately and hunt for signs of compromise.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.