The INC Ransomware group has become the most active operator chaining two SonicWall SMA1000 remote-access vulnerabilities for network compromise, according to threat intelligence firm Resecurity. The flaws, patched earlier this year, have since produced a wave of newly named victims across private and public organizations in the United States, Australia, the United Arab Emirates, Colombia, and Switzerland, and they are now drawing secondary “help desk” scam activity on top of the primary ransom demands.
The two vulnerabilities at the centre of the campaign allow unauthenticated remote attackers to open a WebSocket tunnel to restricted services and to escalate privileges to root on SMA1000 appliances. CVE-2026-15409 carries a CVSS score of 10.0, while CVE-2026-15410 is rated 7.2. Resecurity reports that the INC group is now the most active threat actor chaining the pair to compromise the devices, and the group has accelerated its activity in early August by listing multiple new victims on its data leak site.
How CVE-2026-15409 and CVE-2026-15410 Grant Root Access on SMA1000
The SMA1000 line is commonly deployed as a secure remote-access gateway, which makes these two flaws particularly consequential. CVE-2026-15409 lets an unauthenticated attacker open a WebSocket tunnel to restricted services on the appliance, while CVE-2026-15410 escalates privileges to root. Together they give a remote party the control needed to compromise a device that sits at the edge of corporate networks.
UTA0533’s Earlier Exploitation and Credential Harvesting
Researchers who studied earlier exploitation reported that threat actors harvested credentials from hacked appliances and deployed malicious files, though with limited success at moving laterally. Volexity attributed that earlier observed activity to threat actor UTA0533. Security vendor Rapid7 separately documented attackers pivoting from compromised SMA1000 devices into internal corporate networks, likely after deploying a backdoor on the appliance. The same device-level foothold now underpins the INC Ransomware activity.
Rapid7’s Observation of the Pivot Into Corporate Networks
Root access on a remote-access gateway, combined with backdoor persistence, gives attackers a position from which to reach systems beyond the appliance. Once inside, INC Ransomware encrypts systems and threatens data leaks, an approach consistent with the new victims named on its leak site across multiple countries and both private and government sectors.
Victims in Wave 1 and the Secondary Scam Wave
Resecurity says it assisted several victims with digital forensics and incident response and with vulnerability assessments during the campaign. The firm warns that a secondary wave of phone and email solicitations now compounds the primary ransom demand. New victims have reported receiving emails and phone calls from unknown organizations claiming to help with ransomware issues. In one instance, the solicitation email came from a domain registered after the exploitation activity through a Chinese domain registrar.
Fake Helpers and “Pressure Tactics” Follow-Ups
In one described case, a victim who phoned the group was contacted by a caller identifying themselves as “Andrew,” claiming to represent a group of hackers and closing the call by supplying the email address info@helprans[.]com for negotiations. Resecurity characterizes such solicitations as typical ransomware pressure tactics. The pattern shows that INC Ransomware is pairing its direct extortion with a separate, overlapping pool of solicitors who try to profit from confusion it creates.
Patch Guidance for SMA1000 and What to Do Next
SonicWall shipped patches for both weaknesses on the same day they were added to CISA’s Known Exploited Vulnerabilities catalog. Resecurity urges administrators to patch SMA1000 appliances immediately rather than waiting, and to perform threat hunting to identify any compromise that may already have occurred. Because root access resided on the appliance, defenders should assume that any device exposed before the patch could have been touched and should inspect for signs of a backdoor before restoring trust.
The secondary scam wave is the more novel warning signal for organizations responding to these incidents. Ransomware victims typically track a single negotiation channel and a single threat actor; the arrival of unverified third parties offering “help” blurs that picture and introduces channels that can steer a victim toward a separate payment. The professional judgment from incident responders here is that the scam activity may outlast the encryption itself, since the domains and phone numbers used to solicit appear tied to the operational window rather than to durable infrastructure. Any organization that saw a remote-access gateway reached this month should audit both the appliance and the network behind it, and should treat anonymous “help desk” outreach as an indicator to report rather than a channel to trust.
