2026-07-14HIGHexploitedSonicWall confirms active exploitation of an unauthenticated SMA1000 SSRF chained to code injection for full appliance takeover
INC Ransom
actor · actor:inc-ransom single-source
Ransomware-as-a-service operation active since ~2023; researchers assess Lynx (active since mid-2024) as an INC rebrand rather than a distinct group. SOCRadar's 2026-07-01 FortiBleed attribution report ties INC/Lynx to the FortiBleed FortiGate credential-theft infrastructure via shared negotiation-panel access and overlapping leak-site victims.
Aliases: INC, INC Ransomware, Lynx
Coverage
3
2 about it · 1 mention · first 2026-05-20 → last 2026-09-30
Latest activity
2026-09-12
SonicWall confirms active exploitation of an unauthenticated SMA1000 SSRF chained to code injection for full…
Peak priority
high
1 high · 1 notable
Targets
public-sector
sectors: public-sector, healthcare, finance · regions: europe, switzerland
Sources cited
15
15 hosts
2026-05-203 appearances2026-07-25
Action items (3)
Do-now tasks recorded on the entries about INC Ransom, newest first. Check the date before acting on an older one.
- Upgrade every internet-facing SonicWall SMA1000 (6210/7210/8200v) to platform-hotfix 12.4.3-03453 or 12.5.0-02835 now; active exploitation is vendor-confirmed and both CVEs are KEV-listed; SMA100-series and firewall-hosted SSL-VPN are not affected, so scope the emergency change to SMA1000 only.2026-07-14CVE-2026-15409 +1
- Treat any SonicWall SMA 1000 that was internet-exposed and unpatched before the hotfix as compromised, not merely vulnerable: re-image rather than patch in place, then reset all account passwords and TOTP seeds, UTA0533 established on-appliance persistence and captured cleartext LDAP credentials, so stolen secrets and implants survive the patch.2026-07-14CVE-2026-15409 +1
- On every SMA 1000 you remediated for CVE-2026-15409/-15410, re-verify the installed firmware version now (Rapid7 observed the actor rolling an applied patch back to a vulnerable state) and widen the credential rotation beyond account passwords and TOTP seeds to directory-service bind credentials for LDAP/RADIUS/Active Directory and every certificate and API key configured on the appliance.2026-07-14CVE-2026-15409 +1
Defender insights
What each entry about INC Ransom tells a defender to do, newest first.
Latest update · triage
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
overlaps with
- UTA0533Rapid7 states the technical correlation indicates a single actor or coordinated group is responsible for discovering and exploiting the SonicWall SMA 1000 chain that Volexity tracks as UTA0533. A correlation claim only; Volexity has published no INC link, so this is never upgraded to attribution or a merge.
related to
- Microsoft DCU Fox Tempest disruptiondownstream user of the disrupted signing service
Story timeline
Every entry that names INC Ransom, newest first. Rows tagged mention only name it in passing: they are listed for completeness and add nothing to the action items, pivots or ATT&CK profile on this page.
- 2026-07-25Swiss autism-support foundation Stiftung Autismuslink confirms data-theft cyberattack; INC Ransom claims it
- 2026-07-14CVE-2026-15409, SonicWall SMA1000: unauthenticated SSRF (CVSS 10.0) chained to post-auth code injection, actively exploited
- 2026-05-20Microsoft DCU disrupts Fox Tempest, a malware-signing service that enabled Rhysida deployments and is linked to INC, Qilin and Akira affiliates
Hunting pivots
CVEs (exploited first)
Affected products
ATT&CK techniques (20 across 12 tactics)
20 techniques observed across 2 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExternal Remote Services · Exploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter
- PersistenceBoot or Logon Initialization Scripts: RC Scripts · External Remote Services · Server Software Component: Web Shell
- Privilege EscalationBoot or Logon Initialization Scripts: RC Scripts · Process Injection · Exploitation for Privilege Escalation
- StealthProcess Injection
- Defense ImpairmentModify System Image: Downgrade System Image
- Credential AccessOS Credential Dumping: Security Account Manager · OS Credential Dumping: LSA Secrets · OS Credential Dumping: DCSync · Network Sniffing · Multi-Factor Authentication Interception · Steal Web Session Cookie
- DiscoveryNetwork Sniffing
- Lateral MovementUse Alternate Authentication Material: Pass the Hash
- CollectionData from Local System
- Command and ControlProxy: Multi-hop Proxy · Ingress Tool Transfer
- ImpactData Encrypted for Impact · Financial Theft
Initial Access TA0001
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
Execution TA0002
T1059Command and Scripting Interpreter×1
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
Persistence TA0003
T1037.004Boot or Logon Initialization Scripts: RC Scripts×1
Adversaries may establish persistence by modifying RC scripts, which are executed during a Unix-like system’s startup. These files allow system administrators to map and start custom services at startup for different run levels. RC scripts require root privileges to modify.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
Privilege Escalation TA0004
T1037.004Boot or Logon Initialization Scripts: RC Scripts×1
Adversaries may establish persistence by modifying RC scripts, which are executed during a Unix-like system’s startup. These files allow system administrators to map and start custom services at startup for different run levels. RC scripts require root privileges to modify.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1055Process Injection×1
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
Stealth TA0005
T1055Process Injection×1
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing arbitrary code in the address space of a separate live process. Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via process injection may also evade detection from security products since the execution is masked under a legitimate process.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
Defense Impairment TA0112
T1601.002Modify System Image: Downgrade System Image×1
Adversaries may install an older version of the operating system of a network device to weaken security. Older operating system versions on network devices often have weaker encryption ciphers and, in general, fewer/less updated defensive features.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
Credential Access TA0006
T1003.002OS Credential Dumping: Security Account Manager×1
Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored. The SAM is a database file that contains local accounts for the host, typically those found with the <code>net user</code> command. Enumerating the SAM database requires SYSTEM level access.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1003.004OS Credential Dumping: LSA Secrets×1
Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts. LSA secrets are stored in the registry at <code>HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets</code>. LSA secrets can also be dumped from memory.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1003.006OS Credential Dumping: DCSync×1
Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process from a remote domain controller using a technique called DCSync.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1040Network Sniffing×1
Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1111Multi-Factor Authentication Interception×1
Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources. Use of MFA is recommended and provides a higher level of security than usernames and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1539Steal Web Session Cookie×1
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
Discovery TA0007
T1040Network Sniffing×1
Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
Lateral Movement TA0008
T1550.002Use Alternate Authentication Material: Pass the Hash×1
Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls. Pass the hash (PtH) is a method of authenticating as a user without having access to the user's cleartext password. This method bypasses standard authentication steps that require a cleartext password, moving directly into the portion of the authentication that uses the password hash.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
Collection TA0009
T1005Data from Local System×1
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Evidence: 2026-07-25/stiftung-autismuslink-bern-inc-ransom-breach · ATT&CK page ↗
Command and Control TA0011
T1090.003Proxy: Multi-hop Proxy×1
Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic traversed before it enters their network; the defender may or may not be able to identify any previous proxies before the last-hop proxy. This technique makes identifying the original source of the malicious traffic even more difficult by requiring the defender to trace malicious traffic through several proxies to identify its source.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×2
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-07-25/stiftung-autismuslink-bern-inc-ransom-breach · 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
T1657Financial Theft×1
Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.
Evidence: 2026-07-14/sonicwall-sma1000-ssrf-cve-2026-15409-actively-exploited · ATT&CK page ↗
Entries about INC Ransom (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Akira×1
- Fox Tempest×1
- KNUCKLEBALL / ORANGETAIL SonicWall SMA toolset×1
- Qilin×1
- Rhysida×1
- SonicWall SMA 1000×1
- SonicWall SMA1000 AMC post-auth code injection (actively exploited)×1
- SonicWall SMA1000 Work Place unauthenticated SSRF (CVSS 10.0, actively exploited)×1
Where this entity is cited
Source distribution
- autismuslink.ch1 (7%)
- blogs.microsoft.com1 (7%)
- darkreading.com1 (7%)
- microsoft.com1 (7%)
- psirt.global.sonicwall.com1 (7%)
- radar.offseq.com1 (7%)
- ransomware.live1 (7%)
- rapid7.com1 (7%)
- other7 (47%)
All cited sources (15)
- autismuslink.chStiftung Autismuslink (victim statement)https://autismuslink.ch/wp-content/uploads/2026_07_Informationsschreiben_zum_Serverausfall_Extern.pdf
- blogs.microsoft.comMicrosoft On the Issues, DCU legal action, 2026-05-19https://blogs.microsoft.com/on-the-issues/2026/05/19/disrupting-fox-tempest-a-cybercrime-service/
- darkreading.comDark Readinghttps://www.darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days
- microsoft.comMicrosoft Threat Intelligence, Exposing Fox Tempest, 2026-05-19https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/
- psirt.global.sonicwall.comSonicWall PSIRThttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008
- radar.offseq.comOffSeq Threat Radarhttps://radar.offseq.com/threat/open-directory-exposes-a-full-sonicwall-sma1000-credential-theft-campaign-250-targets-5-domains-fully-d4ce0567ed92186b
- ransomware.liveRansomware.live (INC Ransom leak-site listing)https://www.ransomware.live/id/YXV0aXNtdXNsaW5rLmNoQGluY3JhbnNvbQ==
- rapid7.comRapid7https://www.rapid7.com/blog/post/etr-rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/
- resecurity.comResecurityhttps://www.resecurity.com/blog/article/from-wsproxy-to-root-inc-ransomware-and-sonicwall-sma-exploit-chain
- securityaffairs.comSecurity Affairshttps://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html
- securityweek.comSecurityWeekhttps://www.securityweek.com/recent-sonicwall-vulnerabilities-exploited-in-ransomware-attacks/
- sonicwall.comSonicWallhttps://www.sonicwall.com/support/notices/product-notice-sma-1000-series-affected-by-multiple-vulnerabilities/kA1VN000001nv6D0AQ
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
- therecord.mediaThe Record, 2026-05-19https://therecord.media/microsoft-disrupts-fox-tempest-malware-signing-service
- volexity.comVolexityhttps://www.volexity.com/blog/2026/07/17/proxying-to-compromise-sonicwall-secure-mobile-access-0-day-exploitation/