hacker-news · Crawled Aug 3, 2026

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

4 IoCs
Read original article ↗

AI Summary

The INC Ransomware group has become the dominant threat actor exploiting zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances, specifically CVE-2026-15409 and CVE-2026-15410, which allow for arbitrary command execution. The group has exploited these flaws since at least June 22, 2026, deploying a Python script called KNUCKLEBALL to launch the Suo5 proxy and a custom Java web shell named ORANGETAIL. Victims span multiple countries including the U.S., Australia, and Switzerland, with attackers using social engineering tactics such as phone calls from an individual claiming to be 'Andrew' and using the number +1 (304) 384-0401 to pressure victims into negotiations via info@helprans[.]com.

AI-extracted · verify before operational use

Indicators of Compromise 4 extracted

Type Value Detail
Domain helprans[.]com Details →
Filename KNUCKLEBALL Details →
Filename ORANGETAIL Details →
IP 304[.]384[.]0401 Details →