INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations.
Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since early August, targeting organizations across the United States, Australia, the United Arab Emirates, Colombia, Switzerland, and other countries.
Resecurity estimates that the exploitation of CVE-2026-15409 and CVE-2026-15410 could significantly aid Initial Access Brokers (IABs) in gaining unauthorized access to targets of interest. Both vulnerabilities have been added to the CISA Known Exploited Vulnerabilities Catalog. Beyond exploiting the SonicWall flaws, Resecurity observed the ransomware operators using phone calls and emails as pressure tactics during extortion negotiations, highlighting the evolution of ransomware campaigns into coordinated multi-channel operations.
Organizations operating SonicWall SMA 1000 appliances remain at immediate risk if vulnerable systems have not been patched or investigated for compromise. Enterprises that rely on VPN appliances for remote access should also be aware that compromised gateways can provide attackers with privileged access to credentials, session data, and internal networks before ransomware deployment.
For example, the domain name associated with one of these emails (used by threat actors to contact the victim organization) was registered shortly after the actual incident and the exploitation activity, which Resecurity believes began in June 2026, prior to the release of the official advisory and the availability of the patch. The domain name was registered through a Chinese domain registrar that accepts cryptocurrency payments.
- Domain Name: HELPRANS[.]COM
- Registry Domain ID: 3106477703_DOMAIN_COM-VRSN
- Registrar WHOIS Server: whois.ordertld.com
- Registrar URL: http://www.ordertld.com
- Updated Date: 2026-06-02T11:54:59Z
- Creation Date: 2026-06-02T10:48:13Z
- Registry Expiry Date: 2027-06-02T10:48:13Z
- Registrar: CNOBIN INFORMATION TECHNOLOGY LIMITED
- Registrar IANA ID: 3254
- Registrar Abuse Contact Email: abuse@ordertld.com
- Registrar Abuse Contact Phone: +852.30501810
- Domain Status: clientTransferProhibited https://lnkd.in/deefCcwu
- Name Server: DENVER.NS.CLOUDFLARE.COM
- Name Server: TESSA.NS.CLOUDFLARE.COM
The victims were also contacted by an individual who introduced himself as “Andrew” using the phone number +1 (304) 384-0401. He claimed to be calling “from a group of hackers” and stated that the victim’s network had been compromised. At the end of the call, the individual provided the email address info@helprans[.]com for further negotiations and then ended the call. Such methods are frequently used by ransomware groups as “pressure tactics.”
Resecurity recommends immediately contacting law enforcement if your organization faces such extortion demands.
What CISOs should do:
- Immediately patch SonicWall SMA 1000 appliances, verify that systems have not already been compromised, and conduct threat hunting for indicators of post-exploitation activity.
- Rotate privileged credentials, invalidate active VPN sessions where appropriate, and review authentication logs for evidence of credential theft or unauthorized administrative access.
- Prepare incident response teams for modern ransomware tactics that combine technical compromise with direct phone and email contact intended to pressure victims into paying ransoms.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, INC Ransomware)
