INC Ransomware Chained Two SonicWall Flaws Into 885 Claimed Victims
Cybersecurity

INC Ransomware Chained Two SonicWall Flaws Into 885 Claimed Victims

A single actor was exploiting a SonicWall SMA 1000 vulnerability chain weeks before a patch existed, and researchers now tie the group to nearly 900 posted victims and a wave of fake incident-response calls pressuring companies to pay.

PublishedAugust 8, 2026
Read time6 min read
Share

The vulnerability chain

SonicWall's Secure Mobile Access 1000 series appliances, widely deployed as remote access gateways for corporate networks, contain two flaws that INC ransomware has been chaining together: CVE-2026-15409 and CVE-2026-15410. Used in combination, the pair gives an attacker arbitrary command execution and effective takeover of the appliance itself, a far more serious outcome than either flaw would produce alone, and one that hands an attacker the same level of trust the appliance normally reserves for legitimate remote employees connecting from outside the corporate network.

SonicWall shipped patches for both vulnerabilities in mid-July 2026. Rapid7's vulnerability intelligence team found technical evidence that exploitation began as early as June 22, 2026, roughly three weeks before a fix existed. That gap means organizations that patched promptly on release day were still potentially compromised weeks earlier, and patch timing alone does not establish whether an appliance was already breached before the update landed. Any SMA 1000 deployment that was internet-facing during that pre-patch window needs to be treated as a potential intrusion point regardless of when the patch was ultimately applied.

What the exploit chain actually gets attackers

Once inside, the exploitation chain is used to extract high-value credentials and active session databases directly from the appliance, along with Time-Based One-Time Password seed configurations used for multi-factor authentication. Stealing TOTP seeds is a specific and serious escalation: it lets an attacker generate valid MFA codes going forward, defeating the exact control organizations rely on to stop credential theft from turning into account takeover, and doing so without triggering any of the alerts a stolen password or failed login attempt would normally raise.

Attackers deploy a specific toolset once they have that access: KNUCKLEBALL, a Python script; Suo5, an open-source HTTP tunneling proxy; and ORANGETAIL, a custom Java web shell used to maintain a persistent, hard-to-detect foothold on the compromised appliance. Rapid7's Director of Vulnerability Intelligence noted that the strong technical correlation across observed intrusions indicates a single threat actor or tightly coordinated group is responsible for discovering and exploiting the chain, rather than the flaw circulating widely and quickly across many unrelated groups the way some mass-exploited vulnerabilities do.

The scale INC has claimed

INC ransomware's data leak site lists 885 total victims to date. New postings between July 17 and August 1, 2026 alone span organizations in Australia, the United States, the United Arab Emirates, Colombia, and Switzerland, indicating the group is operating the SonicWall chain against a genuinely global target list rather than concentrating on a single region or sector. The group's activity accelerated noticeably in early August 2026, with its most recent victim listed on August 2, a pace that suggests the exploit chain is being run at scale rather than reserved for hand-picked, high-value targets, and that scale is exactly what makes a single unpatched appliance in a mid-market company's network worth the trouble of chaining two separate CVEs together.

Researchers describe INC as having emerged as the dominant actor actively weaponizing this specific SonicWall vulnerability chain, distinguishing it from opportunistic scanning by less organized groups. That distinction matters operationally: a dominant, well-resourced actor running a known exploit chain against a widely deployed remote access product is a materially different risk than a low-skill group probing the same flaws without a reliable path to full compromise. It also means the group has both the operational maturity and the incentive to keep refining the chain against new targets rather than moving on once initial victims are exhausted.

The social engineering layer

Beyond the technical intrusion, victims have reported receiving unsolicited phone calls and emails from individuals claiming to offer help resolving a ransomware issue. One caller identifying himself as "Andrew" referenced the victim's network compromise directly and pointed them to a negotiation contact address, a pressure tactic layered on top of the technical breach rather than a separate incident, designed to make the extortion feel more personal and harder to ignore than a leak site posting alone would.

This kind of follow-up contact is designed to create urgency and confusion during the exact window when an organization's incident response team is trying to establish ground truth about what happened. Security teams should treat any unsolicited inbound contact referencing an active or suspected compromise as a social engineering attempt by default, and route it through the incident response lead rather than allowing individual employees to engage with callers claiming inside knowledge of the breach.

Immediate remediation, and its limits

Rapid7's guidance for organizations running affected SMA 1000 appliances is direct: patch immediately to the latest version, rotate all credentials that touched the appliance, and conduct comprehensive threat hunting rather than assuming a clean patch means a clean environment. Specific hunting guidance includes identifying external addresses interacting with the appliance's /wsproxy endpoint using unusual parameters and correlating any hits against internal authentication logs and lateral movement indicators, since the appliance itself may show no obvious signs of compromise once the attacker has moved deeper into the network.

Because the exploitation window predates the patch by roughly three weeks, organizations that patched on schedule still need to run that threat hunt retroactively rather than treating the update as closing the incident. Given that the chain specifically targets TOTP seed extraction, any organization that has not independently reissued MFA seeds since the June 22 exploitation start date should treat its current MFA posture on affected systems as unverified rather than trusted.

The broader pattern for remote access appliances

SonicWall's SMA line joins a growing list of remote access and VPN appliances, alongside similar products from other vendors, that have become preferred ransomware entry points precisely because they sit at the network perimeter with privileged access by design. A single chained vulnerability in that class of device tends to be worth more to a ransomware operator than a dozen scattered flaws in internal applications, because the appliance is built to grant exactly the kind of broad, persistent access attackers want.

For any organization running SMA 1000 or comparable remote access gateways, the SonicWall chain is a concrete argument for treating perimeter appliance patching on an accelerated timeline separate from general patch management cycles, with credential rotation and MFA seed reissuance built in as a default response to any disclosed vulnerability in that product class, not just the ones already confirmed as exploited. Waiting for confirmed exploitation before rotating credentials on a perimeter appliance means accepting the same three-week exposure window that INC's victims already lived through this summer.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#inc-ransomware#sonicwall#cve-2026-15409#cve-2026-15410#remote-access-vpn#mfa-bypass#rapid7#patch-management