Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Greece’s Mitsotakis: EU needs new tools to fight back against weaponized migration – POLITICO

    August 4, 2026

    I tried buying a MacBook Air from Apple today – shipping was delayed by over a month

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Greece’s Mitsotakis: EU needs new tools to fight back against weaponized migration – POLITICO
    • I tried buying a MacBook Air from Apple today – shipping was delayed by over a month
    • New Pass-ta-key attacks let malware hijack Google-synced passkeys
    • Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too
    • Two new compounds could reveal hidden drivers of Alzheimer’s disease
    • Why did San Diego County stall wage theft reforms?
    • Australia news live: cabinet shake-up in Victoria; Tabcorp and Sportsbet say ‘no evidence’ they provided drugs and escorts to customers | Australia news
    • An Emerging Deal Between Iran and Oman to Reopen Hormuz Would Come at a Cost for Trump
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 4
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 4, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 03, 2026Vulnerability / Cybercrime

    The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.

    In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per statistics listed on Ransomware.Live, the group has claimed 885 victims to date, with the most recent victim listed on August 2, 2026.

    The attacks are suspected to involve the exploitation of CVE-2026-15409 and CVE-2026-15410, which could be chained to facilitate arbitrary command execution and take over susceptible devices. Fixes for the vulnerability pair were released by SonicWall in mid-July 2026.

    The two shortcomings are assessed to have been weaponized as zero-days, with Rapid7 noting that the attacks leveraged the foothold to extract high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication (MFA) seed configurations with an aim to ensure long-term, persistent access and ultimately carry out lateral movement into the internal corporate network.

    In a follow-up report, Volexity attributed the pre-disclosure exploitation starting June 22, 2026, to a threat cluster it tracks as UTA0533. The attacks involve the deployment of a Python script named KNUCKLEBALL that’s used to launch Suo5, an open-source HTTP proxy, and a Behinder-like custom Java web shell dubbed ORANGETAIL.

    Rapid7 subsequently told The Hacker News that the campaign shares significant tactical overlaps with its own investigations.

    “This strong technical correlation indicates that a single threat actor or coordinated group is responsible for discovering and exploiting this zero-day vulnerability,” Douglas McKee, director of vulnerability intelligence at Rapid7, said. “More recently, INC Ransomware has emerged as the dominant threat actor actively weaponizing this vulnerability chain.”

    Cybersecurity

    Resecurity said the new victims listed on INC Ransomware’s site between July 17 and August 1, 2026, include private sector and government organizations from Australia, the U.S., the U.A.E., Colombia, Switzerland, and other countries.

    The cybersecurity company also revealed, “many of the new victims received emails, as well as phone calls from unknown organizations claiming to assist with ransomware issues.” In some cases, the victims are also said to have been contacted by an individual who went by the name “Andrew” using the phone number +1 (304) 384-0401.

    “He claimed to be calling ‘from a group of hackers’ and stated that the victim’s network had been compromised,” the company noted. “At the end of the call, the individual provided the email address info@helprans[.]com for further negotiations and then ended the call. Such methods are frequently used by ransomware groups as ‘pressure tactics.'”

    Customers are advised to immediately patch SMA 1000 appliances to the latest version, if not already. Resecurity has also recommended comprehensive threat hunting, credential rotation, and integrity verification alongside patching to safeguard against the threat.

    “Identify external source addresses that interacted with /wsproxy or used unusual parameters, and correlate with internal authentication and lateral-movement activity,” it added.

    actor Dominant emerges exploiting flaws ransomware SMA SonicWall
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

    Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion

    Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    Fake Roblox Xeno script launcher pushes infostealer, RAT malware

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Greece’s Mitsotakis: EU needs new tools to fight back against weaponized migration – POLITICO

    August 4, 2026

    I tried buying a MacBook Air from Apple today – shipping was delayed by over a month

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026

    Marmot Researchers Turn to OnlyFans for Funding—And There Are Meme Coins Too

    August 4, 2026
    Latest Posts

    A Russian Spy, Suddenly Cast Into the Spotlight, Flees Japan

    July 23, 2026

    Did Trump accidentally declassify proof Russia tried to help him win 2020 election?

    July 23, 2026

    Trump Puts Section 338 Tariffs on Canada as Greer Foreshadows New Global Duties

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Greece’s Mitsotakis: EU needs new tools to fight back against weaponized migration – POLITICO

    August 4, 2026

    I tried buying a MacBook Air from Apple today – shipping was delayed by over a month

    August 4, 2026

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    August 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.