SonicWall CVE-2026-15409 Exploited by Inc Ransomware

Inc Ransomware, the ransomware-as-a-service (RaaS) group, has exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 Series appliances. The vulnerabilities, identified as CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 (CVSS 7.2), allow unauthenticated attackers to achieve remote code execution and gain root-level privileges on affected devices. This exploitation has led to direct infiltration of multiple enterprise networks, with confirmed instances of ransomware deployment.

Telemetry from Rapid7 initially detected unidentified threat actors using these flaws for initial access. Further analysis specifically attributed the activity to Inc Ransomware, showing a complex intrusion chain that includes bypassing input validation controls, executing operating system-level commands, and establishing persistent access. The group has been observed stealing credentials and active session databases, which allows lateral movement across corporate networks, with a particular focus on domain controllers.

The importance of these vulnerabilities was emphasized by the Cybersecurity and Infrastructure Security Agency (CISA), which added both CVE-2026-15409 and CVE-2026-15410 to its Known Exploited Vulnerabilities (KEV) catalog on July 14, 2026. While SonicWall has released a hotfix to address these issues, incident response experts emphasize that patching alone is insufficient. A full forensic review is essential to ensure complete removal of threat actors who may have already established persistence.

How Inc Ransomware are exploiting SonicWall SMA zero-days

Inc Ransomware has been chaining CVE-2026-15409 and CVE-2026-15410 to fully compromise SonicWall SMA 1000 Series appliances. CVE-2026-15409 is a server-side request forgery (SSRF) flaw in the SMA's "Work Place" web interface, allowing unauthenticated attackers to trick the portal into making requests to internal services. This vulnerability carries a maximum CVSS score of 10.0.

The second vulnerability, CVE-2026-15410, is a code injection flaw that allows arbitrary operating system-level command execution, with a CVSS score of 7.2. While it requires an attacker to already have access to the Appliance Management Console (AMC), it becomes effective when combined with the SSRF vulnerability. Threat actors exploit CVE-2026-15409 to establish initial code execution, then use CVE-2026-15410 to escalate privileges from an unauthenticated outsider to a root-level insider.

The attack flow observed by Rapid7 involves several stages:

  • Initial Access: Exploiting the chained zero-days in internet-facing SonicWall SMA appliances.
  • Bypass and Execution: Bypassing input validation controls to execute commands at the operating system level.
  • Persistence: Stealing credentials, active session databases, and seeds for one-time login codes to maintain access.
  • Lateral Movement: Moving from compromised SMA devices across the corporate network, frequently targeting domain controllers.

This approach allows Inc Ransomware to secure a foothold and expand access, ultimately deploying their ransomware payload. One active case has confirmed ransomware deployment, which shows the immediate and severe impact of these vulnerabilities. The continuous targeting of SonicWall products by ransomware and advanced persistent threat groups is well-documented, reflecting the high value of compromising network edge devices. Further insights into the group's activities can be found in research on Inc Ransomware's surge and FortiBleed exploitation.

SonicWall responded by releasing a hotfix on July 14, 2026. However, security experts caution that simply applying patches is insufficient if an appliance has already been compromised. Attackers have been observed maintaining persistence, sometimes rolling back newly applied patches to a vulnerable state. A full forensic review is important to identify and remove persistent threat actors entirely. For deeper technical analysis on related SonicWall vulnerabilities, previous research has detailed exploitation of SonicWall SMA 1000 zero-days and SonicWall VPN zero-day exploitation.

What data was exposed in the Kudankulam Nuclear Power Plant leak?

The Kudankulam Nuclear Power Plant (KNPP) in Tamil Nadu, India, has been indirectly affected by a data leak resulting from a WORLDLEAKS ransomware attack on Reliance Infrastructure (RINFRA). On June 11, 2026, the WORLDLEAKS group, a spin-off of Hunters International (itself a variant of the former Hive Ransomware Group), listed RINFRA as a victim on its data leak site (DLS). After a two-day countdown, the group published a 1.2TB database belonging to RINFRA.

Within this massive dataset, approximately 18,997 files totaling 14.3GB were found to be directly related to KNPP. The exposed information, while not directly compromising reactor systems or nuclear security according to NPCIL (Nuclear Power Corporation of India Limited), presents significant risks due to its sensitive nature. The data categories include:

  • Financial Records: Documents detailing transactions between Reliance Infrastructure and NPCIL.
  • Tender Documents: Proposals and agreements related to plant construction and operations.
  • Mechanical Records: Information concerning key infrastructure components, such as the Chiller Building, Compressor Building, and Engineering Utilities.
  • Equipment Layout Drawings: Detailed schematics and blueprints of plant equipment.
  • Service Bills: Records of maintenance and other services provided.
  • Vendor Records: Details on third-party suppliers, including Zero Aircon (Air Handling Units), Kruger (Centrifugal Fans), and Ercon Composites (GRP Cable Tray).
  • Employee Data: Information about personnel.
  • Technical Specifications: Including Request for Comment (RFC) Drawings and other design documents.
  • Email Records: Internal communications that could reveal operational details.
  • Internal Conflicts: Documents showing product unavailability or other operational challenges.

Files posing the highest security risk include RFC Drawings and Layouts, documents related to the Physical Protection System (PPS) fencing design, and mentions of Reactor Building tenders and important system components like HVAC and seismic categorizations for transformers. These could be used for industrial espionage or cyber sabotage.

The root cause of the KNPP data exposure is attributed to a third-party vendor, Yotta, which hosted Reliance Infrastructure's servers. Yotta confirmed suspicious activity on May 29, 2026, aligning with the WORLDLEAKS announcement. The WORLDLEAKS group used its in-house data exfiltration tool, RustyRocket (MD5: bcdc36ad84372cf65cda72a3332bacd3), for the breach. This tool has both Windows and Linux builds, with various SHA-256 samples observed. WORLDLEAKS has previously targeted 173 victims across 29 countries, predominantly in the US and UK, with healthcare, manufacturing, and business services being their most targeted sectors.

How CylindricalCanine breached DigiCert and stole code-signing certificates

The CylindricalCanine threat activity cluster, a subgroup of the Chinese cybercrime group GoldenEyeDog (also known as APT-Q-27, Dragon Breath, and Miuuti Group), was responsible for the April 2026 security incident at DigiCert, a major code-signing certificate provider. The breach enabled CylindricalCanine to steal and abuse code-signing certificates, specifically using them to sign their own malware.

The attack began when a threat actor contacted DigiCert's support team via a customer chat channel, delivering a ZIP file disguised as a customer screenshot. This file contained a .scr executable embedded with a malicious payload. Upon execution on two support analyst workstations, the payload provided CylindricalCanine with unauthorized access to DigiCert's internal support portal.

Within the portal, the threat actor used a limited function designed to allow support analysts to access customer accounts from the customer's perspective. This enabled them to view initialization codes for approved, but pending delivery, EV Code Signing certificate orders across a finite set of customer accounts. The possession of these initialization codes, combined with approved orders, was functionally sufficient to obtain actual EV Code Signing certificates.

DigiCert subsequently revoked 60 fraudulently obtained certificates issued by several Certificate Authorities, including:

  • DigiCert Trusted G4 Code Signing RSA4099 SHA256 2021 CA1
  • DigiCert Trusted G4 Code Signing RSA4099 SHA384 2021 CA1
  • GoGetSSL G4 CS RSA4099 SHA256 2022 CA-1
  • Verokey High Assurance Secure Code EV

Of these, 27 certificates were explicitly linked to CylindricalCanine's activities and were used to sign artifacts of the Zhong Stealer malware. The core malware employed by CylindricalCanine is a modified version of Gh0st RAT, known as Golden Gh0st RAT, delivered via a Golden Gh0st Loader. This modular remote access trojan is typically distributed through multi-stage loaders, sometimes using NSIS installers disguised as legitimate software like Google Chrome.

GoldenEyeDog is known for targeting the gambling and gaming sectors, as well as customer support staff in Web3 companies and finance organizations in the Asia-Pacific region. The Golden Gh0st RAT provides extensive capabilities, including persistence, data theft from popular applications (Skype, Google Chrome, Mozilla Firefox, 360 Secure Browser, 360 Speed Browser, Tencent QQ Browser), SOCKS proxy tunneling, keystroke logging, screenshot capture, process enumeration, shell command execution, and the ability to drop additional payloads. The incident shows an important vulnerability in trust models, as the threat model did not account for a compromised analyst account viewing initialization codes through the portal function.

How DPRK's Contagious Interview group targets developers

The Contagious Interview group, a DPRK-aligned threat actor tracked as REF9403, has launched a new campaign targeting developers through fake coding job interviews and challenges. This social engineering tactic aims to compromise developer machines and potentially lead to broader supply chain attacks.

The campaign starts with threat actors, such as a user identified as "Maxwell," posting fake job offers in open forums like community Slack workspaces. Once developers express interest, interactions are moved to direct messages, where recipients are provided with trojanized repositories containing malicious, backdoored code. These repositories, which appear as fully functional projects (e.g., a Next.js e-commerce template copied from GreatStackDev's GoCart), are designed to execute malware silently.

A key technique employed is steganography, where malware payloads are hidden within benign-looking SVG image files, such as country flags (AE.svg, AF.svg). These images contain Base64-encoded fragments of the payload embedded within HTML comments. A JavaScript file (serverValidation.js) within the repository is responsible for:

  1. Reading and sorting the SVG files alphabetically.
  2. Extracting the Base64 fragments from the HTML comments.
  3. Reassembling and decoding the fragments using a custom Base64-decoding function (Check()).
  4. Executing the decoded payload via eval(), a method chosen to evade common detection mechanisms that might flag standard decoding functions.

The malicious payload is triggered every time the development server starts, whether via npm run dev or npm start. At the time of Elastic Security Labs' discovery, these trojanized repositories had zero detections by antivirus vendors.

The distributed malware is aligned with OTTERCOOKIE, sharing code similarity, behavioral patterns, and command-and-control (C2) infrastructure with previously documented DPRK activity. This multi-stage malware package combines several capabilities:

  • Browser Credential and Crypto Wallet Stealer:
  • Targets saved credentials (Login Data), autofill data (Web Data), and cryptocurrency wallet extension databases (Local Extension Settings) from browsers like Chrome, Edge, LT Browser, and Brave across Windows, macOS, and Linux.
  • Exfiltrates data from 25 specific cryptocurrency wallet extensions, including MetaMask, Rabby Wallet, Phantom Wallet, and Keplr.
  • On macOS, it also exfiltrates the system keychain database.
  • Masquerades its process title as npm-cache.
  • Exfiltrates data to ldb.rightwidth[.]dev.
  • File Stealer:
  • Performs recursive scans of mounted drives (Windows) or home directories (macOS/Linux) for sensitive files.
  • Targets glob patterns such as .env, .doc, .pdf, .pem, .ini, .secret, .json, .ts, .js, .zsh_history, and .bash_history.
  • Collects any file within paths like .aws, .azure, .config, and .ssh.
  • Excludes many common development and system files, including AI coding tooling extensions like .claude and .cursor.
  • Exfiltrates data to upload.rightwidth[.]dev.
  • Socket.IO-based Remote Access Trojan (RAT):
  • Establishes a persistent C2 channel to controller.rightwidth[.]dev over HTTPS.
  • Includes VM/sandbox detection mechanisms, tagging compromised virtual environments.
  • Sends registration beacons and logs to controller.rightwidth[.]dev and rightwidth[.]dev.
  • Provides interactive shell access, allowing operators to execute commands via child_process.exec().
  • Clipboard Stealer and Windows PE Dropper:
  • For macOS and Windows, it continuously polls for new clipboard content every 500ms, exfiltrating changes to rightwidth[.]dev.
  • On Windows, it attempts to download and execute three second-stage binaries (hostService.exe, printSvc.exe, dhcpSvc.exe) from file.rightwidth[.]dev.

This campaign shows Contagious Interview's adaptability in using social engineering and stealthy malware deployment to target important individuals in software development.

Technical Takeaways

  • Zero-day exploitation of network edge devices is a primary initial access vector: Inc Ransomware's use of CVE-2026-15409 and CVE-2026-15410 in SonicWall SMA appliances shows the significant risk posed by unpatched or poorly monitored internet-facing infrastructure.
  • Supply chain compromises extend beyond direct vendor breaches: The Kudankulam Nuclear Power Plant data leak, stemming from a third-party vendor's compromise by WORLDLEAKS, demonstrates how indirect exposures can affect important national infrastructure.
  • Code-signing certificate abuse allows advanced evasion: CylindricalCanine's breach of DigiCert to steal and use code-signing certificates shows a growing tactic by threat actors to legitimize malicious payloads and bypass traditional security controls.
  • Steganography and social engineering are effective for developer targeting: The Contagious Interview group's use of malware hidden in SVG images delivered via fake coding challenges shows advanced social engineering combined with stealthy technical execution to compromise developer environments.
  • A full forensic review is essential after patching: In cases of zero-day exploitation, applying vendor patches without a full forensic investigation risks leaving persistent threat actors undetected on compromised systems.