INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
AI Summary
The INC Ransomware group has become the dominant threat actor exploiting zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances, specifically CVE-2026-15409 and CVE-2026-15410, which allow for arbitrary command execution. The group has exploited these flaws since at least June 22, 2026, deploying a Python script called KNUCKLEBALL to launch the Suo5 proxy and a custom Java web shell named ORANGETAIL. Victims span multiple countries including the U.S., Australia, and Switzerland, with attackers using social engineering tactics such as phone calls from an individual claiming to be 'Andrew' and using the number +1 (304) 384-0401 to pressure victims into negotiations via info@helprans[.]com.
AI-extracted · verify before operational use