INC ransomware cashes in on SonicWall SMA1000 zero-day chain

The INC ransomware gang is the most active user of two exploited SonicWall SMA1000 flaws, adding victims across five countries to its leak site.

CSBadmin
2 Min Read

Resecurity ties most of the recent exploitation hitting SonicWall’s SMA1000 secure remote access appliances to the INC Ransomware group.

The pair, CVE-2026-15409 and CVE-2026-15410, carry CVSS scores of 10 and 7.2 respectively, and allow unauthenticated remote attackers to open a WebSocket tunnel to restricted services and climb to root privileges. SonicWall patched them on July 14, and CISA added both to its Known Exploited Vulnerabilities catalog the same day. The bugs had been exploited as zero-days since at least June 22.

Volexity attributed earlier exploitation to an actor tracked as UTA0533, which harvested credentials and dropped malicious files. Rapid7 watched intruders move from hijacked SMA1000 units into internal corporate networks, probably after planting a backdoor.

Resecurity says INC Ransomware has accelerated: since the start of August, its data leak site has listed new victims in the US, Australia, UAE, Colombia and Switzerland. The firm has helped several victims with incident response and vulnerability assessments.

Resecurity also flagged pressure tactics: victims received emails from unknown organizations claiming to help with ransomware issues, one from a domain registered after the exploitation activity through a Chinese registrar, plus phone calls from someone calling themselves Andrew who offered an email address for negotiations.

Users should patch SMA1000 appliances immediately and hunt for signs of compromise.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.