Ransomware Crew Poses as “Ransomware Help”

Resecurity · High sophistication
Last updated August 1, 2026

After exploiting SonicWall SMA 1000 VPN appliances, attackers tied to INC Ransomware reportedly contacted victims directly using emails and phone calls claiming they could help with “ransomware issues.” One caller said he was “from a group of hackers,” asserted the network was compromised, and pushed the victim to continue negotiations over an email address linked to a newly registered domain (helprans[.]com).

Key findings

  • Resecurity reports that some new INC Ransomware victims received emails and phone calls from unknown organizations claiming to help with ransomware issues.
  • A domain used to contact at least one victim (helprans[.]com) was registered shortly after the incident timeframe and before the vendor advisory, suggesting planning around the exploitation wave.
  • A caller identifying himself as “Andrew” claimed to be calling “from a group of hackers,” said the network was compromised, and provided info@helprans[.]com for negotiations, described as a ransomware “pressure tactic.”
  • Separately from the social engineering, the article describes active exploitation of SonicWall SMA 1000 series via CVE-2026-15409 and CVE-2026-15410 leading to root access and malware deployment.

Who’s being targeted

  • Commonly targeted roles: IT, Security, Executive leadership, Helpdesk/Service Desk, Legal/Compliance.
  • Affected industries: Government, Private sector (multiple industries), Critical infrastructure.
  • Attack channels: vishing, email.
  • Impersonated: A member of a 'group of hackers' (ransomware operator/affiliate), A ransomware ‘help’/negotiation service.

Awareness takeaways

  • Treat unsolicited “incident help” emails/calls as potentially attacker-driven pressure tactics; verify any responder through a trusted, independent channel before engaging.
  • If someone claims your organization is compromised and directs you to negotiate via a new/unknown domain or email, escalate immediately to your internal incident process and law enforcement.
  • Be cautious of newly registered domains used for ‘support’ or ‘negotiation’ during an incident; domain age and registration context can be a strong warning sign.

Red flags to watch for

  • Unsolicited call asserting a compromise and demanding direct negotiation
  • Caller claims to be “from a group of hackers” rather than an accountable incident response firm
  • Pushes the victim to switch channels to an unverified external email address
  • Domain created very recently and not tied to a known, reputable incident response provider
  • Unsolicited outreach shortly after an incident, pressuring the victim to engage
  • Contact details and domain registration patterns inconsistent with legitimate firms
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’ve just had a ransomware scare… and then your phone rings. Someone says, “I’m Andrew, from a group of hackers.” He says your network is already compromised and tells you to email info@helprans.com to keep “negotiations” going. Same story shows up in your inbox too. Here’s the trick: INC Ransomware crews are posing as “ransomware help.” They even spun up the domain helprans.com right after attacks, just to pressure victims into talking directly to them. If anyone claims your network is hacked and wants you to email a new domain like helprans.com, hang up and immediately escalate through our internal incident process, don’t reply to them at all.

Categories

Similar attacks

“Ransom Busters” Emails Victims for $60K “Help”

“Ransom Busters” Emails Victims for $60K “Help”

A criminal actor calling itself “Ransom Busters” is emailing organizations that recently suffered ransomware incidents, claiming it hacked ransomware groups’ servers and can delete the victim’s stolen data for a $20,000–$60,000 fee. The messages ask to speak with the CEO or IT leadership and…

August 18, 2026
UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

UNC6671 Vishing: Fake IT Passkey ‘Migration’ Scam

Google reports UNC6671 is still actively compromising organizations by calling employees and pretending to be IT helpdesk staff running an urgent security migration. Victims are pushed to visit lookalike login pages that steal passwords and MFA codes, which then enables data theft and extortion…

August 6, 2026
BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

BlueMoon Phishing Lures Drop Chrome Zero-Day Chain

Researchers found multiple espionage groups using the same Chrome+Windows exploit kit (“BlueMoon”) within days of each other. The groups sent realistic phishing emails (internship requests, conference outreach, procurement inquiries, and vaccination appointments) that pushed victims to click links…

September 10, 2026
Fake IT Help-Desk Calls Steal M365 Sessions

Fake IT Help-Desk Calls Steal M365 Sessions

Arctic Wolf reports a wave of phone-based social engineering where attackers pose as internal IT, guide executives through “routine” MFA/passkey setup, and then send a company-branded login link that steals Microsoft 365 credentials and session tokens. Once inside, attackers methodically inventory…

September 8, 2026
AI-Aided Crypto Scam Used Phishing + Vishing Combo

AI-Aided Crypto Scam Used Phishing + Vishing Combo

Researchers found a crypto fraud operation that used AI-assisted tooling to sift and verify over 100,000 phone numbers, then target confirmed crypto users. The campaign used a one-two approach: phishing messages that included a case/verification code, followed by phone calls that referenced those…

August 19, 2026
Crypto Scam Used Email + Vishing + Fake Wallet Apps

Crypto Scam Used Email + Vishing + Fake Wallet Apps

Rapid7 uncovered an active cryptocurrency fraud operation that combined phishing emails, follow-up phone calls, and counterfeit wallet apps to trick victims into handing over wallet recovery (seed) phrases. The attackers validated and enriched phone-number leads first, then used matching “support…

August 17, 2026