Ransomware Crew Poses as “Ransomware Help”

Resecurity · High sophistication
Last updated August 1, 2026

After exploiting SonicWall SMA 1000 VPN appliances, attackers tied to INC Ransomware reportedly contacted victims directly using emails and phone calls claiming they could help with “ransomware issues.” One caller said he was “from a group of hackers,” asserted the network was compromised, and pushed the victim to continue negotiations over an email address linked to a newly registered domain (helprans[.]com).

Key findings

  • Resecurity reports that some new INC Ransomware victims received emails and phone calls from unknown organizations claiming to help with ransomware issues.
  • A domain used to contact at least one victim (helprans[.]com) was registered shortly after the incident timeframe and before the vendor advisory, suggesting planning around the exploitation wave.
  • A caller identifying himself as “Andrew” claimed to be calling “from a group of hackers,” said the network was compromised, and provided info@helprans[.]com for negotiations, described as a ransomware “pressure tactic.”
  • Separately from the social engineering, the article describes active exploitation of SonicWall SMA 1000 series via CVE-2026-15409 and CVE-2026-15410 leading to root access and malware deployment.

Who’s being targeted

  • Commonly targeted roles: IT, Security, Executive leadership, Helpdesk/Service Desk, Legal/Compliance.
  • Affected industries: Government, Private sector (multiple industries), Critical infrastructure.
  • Attack channels: vishing, email.
  • Impersonated: A member of a 'group of hackers' (ransomware operator/affiliate), A ransomware ‘help’/negotiation service.

Awareness takeaways

  • Treat unsolicited “incident help” emails/calls as potentially attacker-driven pressure tactics; verify any responder through a trusted, independent channel before engaging.
  • If someone claims your organization is compromised and directs you to negotiate via a new/unknown domain or email, escalate immediately to your internal incident process and law enforcement.
  • Be cautious of newly registered domains used for ‘support’ or ‘negotiation’ during an incident; domain age and registration context can be a strong warning sign.

Red flags to watch for

  • Unsolicited call asserting a compromise and demanding direct negotiation
  • Caller claims to be “from a group of hackers” rather than an accountable incident response firm
  • Pushes the victim to switch channels to an unverified external email address
  • Domain created very recently and not tied to a known, reputable incident response provider
  • Unsolicited outreach shortly after an incident, pressuring the victim to engage
  • Contact details and domain registration patterns inconsistent with legitimate firms
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’ve just had a ransomware scare… and then your phone rings. Someone says, “I’m Andrew, from a group of hackers.” He says your network is already compromised and tells you to email info@helprans.com to keep “negotiations” going. Same story shows up in your inbox too. Here’s the trick: INC Ransomware crews are posing as “ransomware help.” They even spun up the domain helprans.com right after attacks, just to pressure victims into talking directly to them. If anyone claims your network is hacked and wants you to email a new domain like helprans.com, hang up and immediately escalate through our internal incident process, don’t reply to them at all.

Similar attacks

How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

July 29, 2026
Chaos RAT Masquerades as Windows Update

Chaos RAT Masquerades as Windows Update

Cisco Talos reports a remote access trojan (msaRAT) linked to the Chaos ransomware group that hides its command-and-control traffic inside legitimate…

July 23, 2026