INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the dominant threat actor exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. Fixes for the vulnerability pair were released by SonicWall in mid-July 2026.
Intelligence analysis by Llama

The INC Ransomware operation has accelerated its activity since the beginning of August 2026, listing multiple victims on its data leak site. The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices.
Imagine a group of hackers using a secret code to break into a company's computer system. They use a special tool to get past the security and then steal important information. This is what the INC Ransomware group is doing, and it's a big problem.
Analysis
A $60B Vote of Confidence
The INC Ransomware operation has emerged as the dominant threat actor exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per statistics listed on Ransomware.Live, the group has claimed 885 victims to date, with the most recent victim listed on August 2, 2026.
Why Cursor?
Fixes for the vulnerability pair were released by SonicWall in mid-July 2026. The two shortcomings are assessed to have been weaponized as zero-days, with Rapid7 noting that the attacks leveraged the foothold to extract high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication (MFA) seed configurations with an aim to ensure long-term, persistent access and ultimately carry out lateral movement into the internal corporate network.
The Road Ahead
In a follow-up report, Volexity attributed the pre-disclosure exploitation starting June 22, 2026, to a threat cluster it tracks as UTA0533. The attacks involve the deployment of a Python script named KNUCKLEBALL that's used to launch Suo5, an open-source HTTP proxy, and a Behinder-like custom Java web shell dubbed ORANGETAIL. Rapid7 subsequently told The Hacker News that the campaign shares significant tactical overlaps with its own investigations.
Key points
- INC Ransomware has emerged as the dominant threat actor exploiting SonicWall SMA 1000 flaws.
- The attacks involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices.
- Fixes for the vulnerability pair were released by SonicWall in mid-July 2026.
- The attacks have resulted in the theft of high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication (MFA) seed configurations.
- Companies affected by the attacks are advised to immediately patch SMA 1000 appliances to the latest version, if not already.
If the companies affected by the INC Ransomware attacks can quickly patch their systems and implement additional security measures, they may be able to minimize the damage and prevent further attacks.
The emergence of INC Ransomware as a dominant threat actor exploiting SonicWall SMA 1000 flaws highlights the importance of timely patching and comprehensive threat hunting to safeguard against the threat. If companies fail to take these measures, they may be vulnerable to further attacks and data breaches.



