On 22 June 2026, a threat cluster tracked by the security firm Volexity as UTA0533 began exploiting two undisclosed vulnerabilities in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances, weeks before SonicWall itself knew the flaws existed. The vulnerabilities, later catalogued as CVE-2026-15409 and CVE-2026-15410, let an attacker with network access to the appliance chain commands together and take it over outright. SonicWall shipped fixes in mid-July 2026. By early August, the exploit chain had moved from quiet, espionage-style access to a full ransomware pipeline.
Once inside an SMA appliance, the attackers were not stealing a password so much as harvesting the appliance's own trust store. Rapid7 documented the group extracting high-value credentials, active session databases and the seed values behind time-based one-time password (TOTP) multi-factor authentication, the exact secrets a legitimate administrator's second factor depends on. With those in hand, lateral movement into the internal network required no further guesswork and no further prompts. INC Ransomware, according to the threat intelligence firm Resecurity, has since emerged as the dominant operator running this exploit chain at scale, accelerating its use from the start of August 2026 and listing new victims on its extortion site days apart.
Resecurity has now counted 885 organisations claimed by INC Ransomware to date, with victims added between 17 July and 1 August 2026 spanning private companies and government bodies in the United States, Australia, the United Arab Emirates, Colombia and Switzerland. In a detail that speaks to the group's confidence, some newly listed victims reported a phone call, not an email, from a man identifying himself only as "Andrew," claiming to represent "a group of hackers" and directing victims to an address for negotiation before any formal ransom note had been served. Pressure, not just encryption, is now part of the product.
The defences that failed here were not weak by conventional standards. Organisations running SonicWall SMA appliances had, in many cases, patched other known vulnerabilities, monitored their networks, and rotated credentials on a reasonable schedule. What they had was a security model that treated a valid session token, extracted from the appliance itself, as sufficient authority to move laterally and eventually to trigger encryption across hundreds of endpoints. No step in that chain asked a human to confirm anything.
A ransomware deployment is an execution event. Before an encryption job can run across a fleet of endpoints, or before a harvested administrative session can be used to disable backups or alter access policies, GoFirm routes a real-time confirmation request to the named authority responsible for that system, on their registered device, out of band from the network the attacker already controls.
A harvested session token or a stolen TOTP seed, however deep the credential theft goes, cannot produce a biometric confirmation on a device it does not hold. The execution boundary holds regardless of how far up the credential chain an attacker climbs.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.
References
1. Lakshmanan, R. 2026. INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws. The Hacker News, 3 August 2026. E
2. The Hacker News. 2026. Two SonicWall SMA 1000 Zero-Days. The Hacker News, July 2026.
3. The Hacker News. 2026. SonicWall SMA Zero-Days Exploited. The Hacker News, July 2026.
Back to Blog
Case Studies·3 min read
The unpatched SonicWall appliance. The stolen credentials. The 885 victims who found out from a leak site.
By GoFirm Team
