INC Ransomware has been leveraging a zero-day exploit in SonicWall's Secure Mobile Access (SMA) 1000 to target global organizations, with a notable surge in operations since early August. The threat actor has been using pressure tactics, including phone calls and emails, to extort victims during its campaigns. Resecurity's research reveals that INC Ransomware has become a dominant force in exploiting the SonicWall vulnerability, affecting organizations in multiple countries, including the United States, Australia, and the United Arab Emirates. The exploit allows the group to compromise SMA 1000 devices, enabling them to launch ransomware attacks. This exploitation is particularly concerning as it occurs before patches are available, putting defenders at a disadvantage1. The use of zero-day exploits by INC Ransomware underscores the need for organizations to prioritize vulnerability management and implement robust security measures to prevent such attacks, as the lack of patches leaves them vulnerable to these types of threats.
INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit
⚠️ Critical Alert
Why This Matters
Zero-day exploitation means the vulnerability is being used before patches exist — defenders are already behind.
References
- SecurityAffairs. (2026, August 4). INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit. *SecurityAffairs*. https://securityaffairs.com/196607/malware/inc-ransomware-is-calling-victims-pressure-tactics-post-sonicwall-zero-day-exploit.html
Original Source
SecurityAffairs
Read original →