Skip to content
ransomwarevulnerabilityCVEcredential-theft

INC ransomware's SonicWall playbook: from WSProxy to root in one chain

3 min read
Share

The vulnerability chain

SonicWall published advisory SNWLID-2026-0008 on July 14, 2026, covering two critical vulnerabilities in the SMA 1000 series VPN appliances: CVE-2026-15409 and CVE-2026-15410. When chained, these vulnerabilities allow an attacker to progress from initial WSProxy access, the WebSocket-based management protocol used by SMA 1000, through to arbitrary command execution and root-level control of the device. Patches were released the same week as the advisory.

Pre-disclosure exploitation

Volexity observed pre-disclosure exploitation beginning June 22, 2026, more than three weeks before SonicWall's advisory. This is a common pattern with VPN appliance vulnerabilities. The attack surface is exposed to the internet by design, so adversaries with knowledge of an unpatched flaw can operate freely while the vendor is still working on a fix. By the time the patch arrives, the attacker population has already had weeks of uncontested access to affected organizations.

INC ransomware's acceleration

INC ransomware has emerged as the dominant actor exploiting this vulnerability chain. Resecurity's research, titled From WSProxy to Root, documents the full exploitation sequence. As of August 2, 2026, INC has claimed 885 victims globally. Accelerated activity was observed starting at the beginning of August. New victims include government and private-sector organizations in Australia, the United States, the UAE, Colombia, and Switzerland. The group is also running a secondary social-engineering tactic: victims receive unsolicited phone calls offering ransomware assistance. This is a known extortion amplification technique designed to delay incident response.

Why VPN appliances keep appearing in this position

SonicWall SMA, Ivanti, Fortinet, Citrix. The list of VPN and remote-access appliances that have served as initial access vectors in major ransomware campaigns is long and growing. These devices sit on the internet edge, run complex proprietary code, have historically received less scrutiny from the security research community than enterprise software, and are difficult to update quickly in production environments. A ransomware group with a working exploit for an internet-exposed edge device has an attack path that scales across many organizations simultaneously. INC has clearly understood this.

What to do

If you operate SonicWall SMA 1000 series appliances, patch to the fixed firmware immediately. Review WSProxy access logs for activity from June 22 onward. Treat any anomalous activity during that window as a potential compromise. INC ransomware uses living-off-the-land techniques post-exploitation, so the indicators in your logs may be subtle. Engage a forensics team if you have any doubt. Both Volexity and Resecurity have published indicators of compromise.

Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you need help scoping your SonicWall exposure or planning incident response.