INC Ransomware is Calling Victims – Pressure Tactics Post SonicWall Zero-Day Exploit
ID: b49a1724-3909-58ed-a78d-72782f56f8e6
STIX ID: report--b49a1724-3909-58ed-a78d-72782f56f8e6
Feed Name: Security Affairs
INC Ransomware is actively exploiting SonicWall SMA 1000 vulnerabilities (CVE-2026-15409, CVE-2026-15410) to gain initial access and deploy ransomware across organizations in multiple countries; operators are using phone calls and emails (domain HELPRANS.COM and phone +1 (304) 384-0401) as pressure tactics during extortion. Resecurity observed exploitation beginning in June 2026 and recommends immediate patching, credential rotation, threat hunting, and contacting law enforcement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
