Full Report
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per
Analysis Summary
# Threat Actor: INC Ransomware
## Attribution & Identity
- **Actor Name:** INC Ransomware
- **Aliases:** UTA0533 (Volexity tracking cluster)
- **Known Associations:** Associated with a coordinated group or single threat actor responsible for the discovery and exploitation of specific SonicWall zero-days. An individual using the name "Andrew" has been linked to negotiation/pressure tactics.
## Activity Summary
INC Ransomware has emerged as the dominant threat actor exploiting vulnerabilities in SonicWall SMA 1000 series appliances. While initial exploitation (as UTA0533) began as early as June 22, 2026, the group significantly accelerated its activity in early August 2026. As of August 2, 2026, the group has claimed approximately 885 victims on its data leak site.
## Tactics, Techniques & Procedures
- **Vulnerability Exploitation:** Chaining of CVE-2026-15409 and CVE-2026-15410 for arbitrary command execution and device takeover.
- **Persistence:** Extraction of active session databases and Time-Based One-Time Password (TOTP) MFA seed configurations to maintain long-term access.
- **Credential Access:** Harvesting high-value credentials from compromised appliances.
- **Lateral Movement:** Moving from the initial VPN appliance foothold into internal corporate networks.
- **Pressure Tactics:** Direct communication with victims via phone calls and emails from "unknown organizations" or individuals (e.g., "Andrew") claiming to assist with the hack to force negotiations.
- **MITRE ATT&CK IDs (Inferred from TTPs):**
- T1190: Exploit Public-Facing Application
- T1555: Credentials from Password Stores
- T1021: Remote Services
- T1556.006: Modify Authentication Process: Multi-Factor Authentication
- T1204: User Execution (via pressure tactic calls)
## Targeting
- **Sectors:** Private sector and Government organizations.
- **Geography:** Australia, United States, United Arab Emirates (U.A.E.), Colombia, and Switzerland.
- **Victims:** 885 total victims claimed to date (specific organization names were not listed in the text).
## Tools & Infrastructure
- **KNUCKLEBALL:** A Python script used to launch secondary payloads.
- **Suo5:** An open-source HTTP proxy used for tunneling.
- **ORANGETAIL:** A custom Java web shell (Behinder-like).
- **Communication/Negotiation Infrastructure:**
- Phone: +1 (304) 384-0401
- Email: info@helprans[.]com
- Leak Site: [Redacted/Dark Web]
## Implications
INC Ransomware has demonstrated a high level of technical sophistication by weaponizing zero-day vulnerabilities before public disclosure. Their focus on extracting MFA seeds indicates a strategic shift toward bypassing modern security controls to ensure persistent access even after initial remediation. The use of direct phone-based harassment marks an aggressive escalation in "double extortion" methodologies.
## Mitigations
- **Patching:** Immediately update SonicWall SMA 1000 series appliances to the latest firmware versions provided in mid-July 2026.
- **Threat Hunting:** Inspect logs for external source addresses interacting with the `/wsproxy` endpoint or using unusual parameters.
- **Identity Security:** Perform a comprehensive rotation of all credentials and MFA seeds that may have been stored on or passed through the affected VPN appliances.
- **Integrity Verification:** Audit internal networks for signs of lateral movement or unauthorized authentication originating from VPN segments.