
INC Ransomware — a prolific group that has now claimed 885 victims — has become the primary threat actor actively weaponising two critical flaws in SonicWall Secure Mobile Access (SMA) 1000 VPN appliances: CVE-2026-15409 and CVE-2026-15410. The pair can be chained together to allow an attacker to execute arbitrary commands and fully take over an exposed device without credentials. SonicWall released patches in mid-July 2026, but threat actors had already been exploiting both vulnerabilities as zero-days since at least June 22, according to attribution by security firm Volexity, which tracks the initial cluster as UTA0533.
Once inside a SonicWall appliance, attackers use a Python loader called KNUCKLEBALL to deploy an open-source HTTP proxy (Suo5) and a custom web shell called ORANGETAIL. The goal is to harvest high-value credentials, copy active session databases, and steal the TOTP seed configurations that underpin multi-factor authentication — giving the attacker the ability to bypass MFA and maintain long-term, persistent access. Rapid7, which has investigated multiple incidents with the same tactical fingerprint, confirmed to The Hacker News that the overlaps point to a single coordinated threat actor or group, with INC Ransomware now leading the exploitation wave into the corporate networks reachable through these VPN gateways.
How to check if you’re affected
Affected products include any SonicWall SMA 1000 series appliance running firmware versions before the mid-July 2026 patch release. Log in to your SonicWall appliance management console, navigate to the firmware version screen, and confirm that firmware updates published in July 2026 are applied. If you manage these devices in a corporate environment, also audit VPN session logs for activity originating from unusual countries or IP ranges since late June 2026, and rotate any MFA seed configurations (TOTP secrets) stored on the appliance, since attackers may have already copied them.
