Full Report
INC ransomware wasn’t the first group to exploit the zero-days, but it’s been the most assertive and effective in chaining both vulnerabilities to steal and encrypt data for extortion. The post Prolific ransomware group behind SonicWall zero-day attacks appeared first on CyberScoop.
Analysis Summary
# Incident Report: INC Ransomware Exploitation of SonicWall Zero-Days
## Executive Summary
The INC Ransomware group has been identified as the primary threat actor weaponizing a chain of two SonicWall zero-day vulnerabilities (CVE-2026-15409 and CVE-2026-15410) to gain full administrative access to target networks. The group has successfully utilized these flaws to steal sensitive data and deploy ransomware for extortion purposes across multiple countries. While initial exploitation began in late June 2026, INC Ransomware became the most assertive operator following the public disclosure of the patches in mid-July.
## Incident Details
- **Discovery Date:** Initial exploitation observed June 22, 2026; INC activity identified post-July 14, 2026.
- **Incident Date:** Ongoing from June 2026 to August 2026.
- **Affected Organization:** Multiple (including government agencies and private corporations).
- **Sector:** Cross-sector (Government, Finance, Healthcare, etc.).
- **Geography:** Global (Australia, United States, UAE, Colombia, Switzerland).
## Timeline of Events
### Initial Access
- **Date/Time:** June 22, 2026 (Earliest observed hits); INC activity surged after July 14.
- **Vector:** Exploitation of SonicWall Zero-Day Vulnerability Chain.
- **Details:** Attackers chained CVE-2026-15409 and CVE-2026-15410 to bypass security and gain entry.
### Lateral Movement
- **Details:** Upon gaining access via the firewall/SMA gateway, attackers moved from the initial entry point to internal servers to deploy ransomware in "short order," demonstrating a high operational tempo.
### Data Exfiltration/Impact
- **Details:** INC Ransomware utilized their access to exfiltrate sensitive corporate and government data to their leak site. In at least one confirmed case, the group successfully encrypted the environment.
### Detection & Response
- **Discovery:** Identified by security researchers (Rapid7, Huntress, Resecurity) through telemetry and monitoring of INC’s data leak site.
- **Response Actions:** SonicWall released patches on July 14, 2026. Security firms such as Rapid7 intervened in several cases to block data theft and encryption attempts.
## Attack Methodology
- **Initial Access:** Weaponization of a zero-day exploit chain targeting SonicWall appliances.
- **Persistence:** Not explicitly detailed, but typical of INC to maintain access via compromised credentials or web shells.
- **Privilege Escalation:** Chaining vulnerabilities to move from unauthenticated access to full administrative ("root") control.
- **Defense Evasion:** Use of legitimate infrastructure and rapid execution to minimize the window for detection.
- **Credential Access:** Harvesting credentials from the compromised SonicWall SMA/VPN gateways.
- **Discovery:** Internal network scanning post-compromise.
- **Lateral Movement:** Moving from the perimeter appliance to internal network assets.
- **Collection:** Gathering sensitive documents for exfiltration.
- **Exfiltration:** Transferring data to attacker-controlled infrastructure for use on their extortion site.
- **Impact:** Data theft and file encryption via ransomware.
## Impact Assessment
- **Financial:** High potential for ransom demands and recovery costs; specific figures not disclosed.
- **Data Breach:** Compromise of sensitive data from nearly 900 victims globally over the group's history, with new victims added recently.
- **Operational:** Business disruption through encryption; at least 30 customers compromised in a single 48-hour window.
- **Reputational:** Public listing of victims on INC’s data leak site and aggressive follow-up via phone calls and emails to pressure negotiations.
## Indicators of Compromise
- **Network Indicators:** Hosted infrastructure associated with INC Ransomware (Specific IPs defanged: `[h]xxp[:]//inc-leak-site[.]onion`).
- **File Indicators:** INC Ransomware encryption binaries and ransom notes.
- **Behavioral Indicators:** Rapid transition from SonicWall appliance login to internal network reconnaissance.
## Response Actions
- **Containment:** Rapid7 and other vendors reported blocking active encryption attempts.
- **Eradication:** Implementation of firmware patches provided by SonicWall.
- **Recovery:** Assisting victims with data restoration and negotiation management.
## Lessons Learned
- **Zero-Day Readiness:** Threat actors are increasingly capable of weaponizing zero-days immediately following (or even before) disclosure.
- **Vulnerability Chaining:** Attackers are not relying on single bugs but are chaining "moderate" flaws to achieve "critical" impact (root access).
- **Edge Device Risks:** Firewalls and VPN gateways remain the most targeted assets due to their position on the network perimeter.
## Recommendations
- **Patch Management:** Prioritize immediate patching of edge devices (SonicWall, VPNs, Firewalls) within 24 hours of a security advisory.
- **Monitor for Anomalies:** Implement logging and alerting for unusual administrative activity originating from perimeter appliances.
- **Zero Trust:** Move toward a Zero Trust Architecture to limit the impact of a perimeter breach, ensuring that a compromised firewall does not grant unfettered access to the internal network.
- **External Exposure:** Minimize the number of management interfaces exposed to the public internet.