Post

INC Ransomware Seizes the Moment With SonicWall Exploits

INC Ransomware Seizes the Moment With SonicWall Exploits

INC Ransomware Surge 🚀

INC ransomware has surged to the forefront of cyber threats this summer. The group now stands as the dominant actor exploiting a pair of critical flaws in SonicWall’s Secure Mobile Access appliances. From modest beginnings in 2023, the operation has claimed more than 885 victims. Ransomware.Live statistics confirm the group’s total at 885 as of August 2.

Technical Details 🔍

Resecurity detailed the technical path in a weekend report. Attackers chain CVE-2026-15409, a pre-authentication bypass in the /wsproxy endpoint, with CVE-2026-15410, a path-traversal flaw in the remove_hotfix function. The combination grants root access on vulnerable SMA 1000 series devices. SonicWall issued fixes in mid-July. Yet many organizations lagged in deployment. Rapid7 had already flagged the activity as zero-day exploitation weeks earlier.

Threat Actor Insights 🕵️‍♂️

Douglas McKee, director of vulnerability intelligence at Rapid7, stated, “This strong technical correlation indicates that a single threat actor or coordinated group is responsible for discovering and exploiting this zero-day vulnerability. More recently, INC Ransomware has emerged as the dominant threat actor actively weaponizing this vulnerability chain.” The SonicWall campaign marks a refinement. Pre-patch exploitation dating to June 22 gave attackers a head start. Volexity attributed early activity to a cluster it calls UTA0533. Rapid7 and Resecurity both see strong overlap with INC’s later wave.

Attack Methods 🔐

Initial access often starts with stolen credentials purchased from brokers or spear-phishing campaigns. When those fail, operators turn to unpatched remote services. Before SonicWall, they hit Citrix, Fortinet, SimpleHelp, and other appliances.

Once inside, operators deploy custom tooling. A Python script called KNUCKLEBALL launches an open-source HTTP proxy named Suo5 and a Behinder-like Java web shell dubbed ORANGETAIL. They extract credentials, active session data, and TOTP MFA seeds. The goal is clear: establish persistent access, move laterally, exfiltrate sensitive files, and then encrypt what remains.

Victim Profile 🎯

Additionally, victims report calls from a man identifying as “Andrew” at +1 (304) 384-0401. He claims the network belongs to a hacker collective and directs negotiations to [email protected]. Healthcare organizations top the list of targets, followed by manufacturing, legal services, technology, construction, and education. U.S. organizations represent over 65 percent of victims.

Recommendations ⚠️

Defenders face a compressed window. Patching remains the first imperative. Resecurity urges immediate threat hunting for connections to /wsproxy with unusual parameters. Rotate credentials, verify system integrity, and monitor for specific user-agent strings and file artifacts left behind: KNUCKLEBALL, ORANGETAIL, ROOTRUN backdoors. Enterprises running SonicWall SMA 1000 gear must assume active targeting, especially those in healthcare, manufacturing, or legal services.

For more details, check the full article: Read full article

This post is licensed under CC BY 4.0 by the author.