ZeroHour
Security Affairspublished ()ingested @securityaffairs

INC Ransomware is Calling Victims - Pressure Tactics Post SonicWall Zero

highRansomware exploited in the wildimportance 60CVE-2026-15409CVE-2026-15410

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-15409
+1 in the same advisory: …15410
Unauthenticated SSRF in SonicWall SMA1000 Appliances

CVE-2026-15409 is a server-side request forgery (SSRF, CWE-918) in the Appliance Work Place interface of SonicWall SMA1000 series appliances. A remote, unauthenticated attacker can trigger the flaw over the network, causing the appliance to issue requests to attacker-influenced or unintended internal locations. Because the CVSS vector scores scope-changed impacts on confidentiality, integrity, and availability, the SSRF is assessed as capable of reaching sensitive internal services, and reporting indicates it is being used alongside a second SMA1000 zero-day in what may be an exploitation chain. Affected organizations are those running SMA1000 appliances, including SMA 6210, SMA 7210, and SMA 8200v models, which typically act as internet-facing remote-access/VPN gateways. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2026-07-14, ransomware use is known, and EPSS assigns an 83.7% probability of exploitation within 30 days, though no public PoC is available.

Do: Apply SonicWall's SMA1000 firmware update per the vendor's instructions immediately, prioritizing appliances with the Appliance Work Place interface reachable from the internet. Because the flaw is in CISA's KEV with known ransomware use and may be chained with a second SMA1000 zero-day, hunt for signs of compromise (unexpected outbound or internal requests, anomalous VPN sessions, follow-on ransomware activity) and restrict internet exposure of the interface in the interim. Federal and critical-infrastructure operators must comply with CISA BOD 26-04, including cloud-service guidance, or discontinue use if mitigations are unavailable.

10.0
group max
85% KEV ransomware
  • SonicWall SMA1000 Appliances (SMA 6210 firmware)
  • SonicWall SMA1000 Appliances (SMA 7210 firmware)
  • SonicWall SMA1000 Appliances (SMA 8200v)
largeon the order of tens of thousands of internet-exposed appliances (estimate)

Indicators of compromiseAll →

TypeIndicatorContext
domainhelprans.comegistrar that accepts cryptocurrency payments. Domain Name: HELPRANS[.]COM Registry Domain ID: 3106477703_DOMAIN_COM-VRSN Registrar
domainwhois.ordertld.commain ID: 3106477703_DOMAIN_COM-VRSN Registrar WHOIS Server: whois.ordertld.com Registrar URL: http://www.ordertld.com Updated Date: 2026-0
Full article488 words · extracted from securityaffairs.com · click to collapse

INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations.

Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since early August, targeting organizations across the United States, Australia, the United Arab Emirates, Colombia, Switzerland, and other countries.

Resecurity estimates that the exploitation of CVE-2026-15409 and CVE-2026-15410 could significantly aid Initial Access Brokers (IABs) in gaining unauthorized access to targets of interest. Both vulnerabilities have been added to the CISA Known Exploited Vulnerabilities Catalog. Beyond exploiting the SonicWall flaws, Resecurity observed the ransomware operators using phone calls and emails as pressure tactics during extortion negotiations, highlighting the evolution of ransomware campaigns into coordinated multi-channel operations.

Organizations operating SonicWall SMA 1000 appliances remain at immediate risk if vulnerable systems have not been patched or investigated for compromise. Enterprises that rely on VPN appliances for remote access should also be aware that compromised gateways can provide attackers with privileged access to credentials, session data, and internal networks before ransomware deployment.

For example, the domain name associated with one of these emails (used by threat actors to contact the victim organization) was registered shortly after the actual incident and the exploitation activity, which Resecurity believes began in June 2026, prior to the release of the official advisory and the availability of the patch. The domain name was registered through a Chinese domain registrar that accepts cryptocurrency payments.

  • Domain Name: HELPRANS[.]COM
  • Registry Domain ID: 3106477703_DOMAIN_COM-VRSN
  • Registrar WHOIS Server: whois.ordertld.com
  • Registrar URL: http://www.ordertld.com
  • Updated Date: 2026-06-02T11:54:59Z
  • Creation Date: 2026-06-02T10:48:13Z
  • Registry Expiry Date: 2027-06-02T10:48:13Z
  • Registrar: CNOBIN INFORMATION TECHNOLOGY LIMITED
  • Registrar IANA ID: 3254
  • Registrar Abuse Contact Email: [email protected]
  • Registrar Abuse Contact Phone: +852.30501810
  • Domain Status: clientTransferProhibited https://lnkd.in/deefCcwu
  • Name Server: DENVER.NS.CLOUDFLARE.COM
  • Name Server: TESSA.NS.CLOUDFLARE.COM

The victims were also contacted by an individual who introduced himself as “Andrew” using the phone number +1 (304) 384-0401. He claimed to be calling “from a group of hackers” and stated that the victim’s network had been compromised. At the end of the call, the individual provided the email address info@helprans[.]com for further negotiations and then ended the call. Such methods are frequently used by ransomware groups as “pressure tactics.”

Resecurity recommends immediately contacting law enforcement if your organization faces such extortion demands.

What CISOs should do:

  • Immediately patch SonicWall SMA 1000 appliances, verify that systems have not already been compromised, and conduct threat hunting for indicators of post-exploitation activity.
  • Rotate privileged credentials, invalidate active VPN sessions where appropriate, and review authentication logs for evidence of credential theft or unauthorized administrative access.
  • Prepare incident response teams for modern ransomware tactics that combine technical compromise with direct phone and email contact intended to pressure victims into paying ransoms.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, INC Ransomware)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/196607/malware/inc-ransomware-is-calling-victims-pressure-tactics-post-sonicwall-zero-day-exploit.html