logo

INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit

ID: b49a1724-3909-58ed-a78d-72782f56f8e6

STIX ID: report--b49a1724-3909-58ed-a78d-72782f56f8e6

Feed Name: Security Affairs

Threat Score
88/100

Date Published: 2026-08-04

Date Updated: 2026-08-06

Author: Pierluigi Paganini

...
...

INC Ransomware is actively exploiting SonicWall SMA 1000 vulnerabilities (CVE-2026-15409, CVE-2026-15410) to gain initial access and deploy ransomware across organizations in multiple countries; operators are using phone calls and emails (domain HELPRANS.COM and phone +1 (304) 384-0401) as pressure tactics during extortion. Resecurity observed exploitation beginning in June 2026 and recommends immediate patching, credential rotation, threat hunting, and contacting law enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.