Ransomware Crew Poses as “Ransomware Help”

Resecurity · High sophistication
Last updated August 1, 2026

After exploiting SonicWall SMA 1000 VPN appliances, attackers tied to INC Ransomware reportedly contacted victims directly using emails and phone calls claiming they could help with “ransomware issues.” One caller said he was “from a group of hackers,” asserted the network was compromised, and pushed the victim to continue negotiations over an email address linked to a newly registered domain (helprans[.]com).

Key findings

  • Resecurity reports that some new INC Ransomware victims received emails and phone calls from unknown organizations claiming to help with ransomware issues.
  • A domain used to contact at least one victim (helprans[.]com) was registered shortly after the incident timeframe and before the vendor advisory, suggesting planning around the exploitation wave.
  • A caller identifying himself as “Andrew” claimed to be calling “from a group of hackers,” said the network was compromised, and provided info@helprans[.]com for negotiations, described as a ransomware “pressure tactic.”
  • Separately from the social engineering, the article describes active exploitation of SonicWall SMA 1000 series via CVE-2026-15409 and CVE-2026-15410 leading to root access and malware deployment.

Who’s being targeted

  • Commonly targeted roles: IT, Security, Executive leadership, Helpdesk/Service Desk, Legal/Compliance.
  • Affected industries: Government, Private sector (multiple industries), Critical infrastructure.
  • Attack channels: vishing, email.
  • Impersonated: A member of a 'group of hackers' (ransomware operator/affiliate), A ransomware ‘help’/negotiation service.

Awareness takeaways

  • Treat unsolicited “incident help” emails/calls as potentially attacker-driven pressure tactics; verify any responder through a trusted, independent channel before engaging.
  • If someone claims your organization is compromised and directs you to negotiate via a new/unknown domain or email, escalate immediately to your internal incident process and law enforcement.
  • Be cautious of newly registered domains used for ‘support’ or ‘negotiation’ during an incident; domain age and registration context can be a strong warning sign.

Red flags to watch for

  • Unsolicited call asserting a compromise and demanding direct negotiation
  • Caller claims to be “from a group of hackers” rather than an accountable incident response firm
  • Pushes the victim to switch channels to an unverified external email address
  • Domain created very recently and not tied to a known, reputable incident response provider
  • Unsolicited outreach shortly after an incident, pressuring the victim to engage
  • Contact details and domain registration patterns inconsistent with legitimate firms
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’ve just had a ransomware scare… and then your phone rings. Someone says, “I’m Andrew, from a group of hackers.” He says your network is already compromised and tells you to email info@helprans.com to keep “negotiations” going. Same story shows up in your inbox too. Here’s the trick: INC Ransomware crews are posing as “ransomware help.” They even spun up the domain helprans.com right after attacks, just to pressure victims into talking directly to them. If anyone claims your network is hacked and wants you to email a new domain like helprans.com, hang up and immediately escalate through our internal incident process, don’t reply to them at all.

Categories

Similar attacks

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 Calls Staff to Steal SaaS Logins

UNC6671 is running real-world voice phishing (vishing) campaigns where callers impersonate IT help desk staff and create urgency around “mandatory” security changes. Victims are pushed to spoofed login pages that capture passwords and MFA codes, enabling attackers to access and steal data from SaaS…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026