Multiple Incidents of 'Sorry' Ransomware Attacks Detected Across China
23 hour ago / Read about 0 minute
Author:小编   

Recently, the National Computer Virus Emergency Response Center, in collaboration with the National Engineering Laboratory for Computer Virus Prevention and Control Technology, has identified multiple incidents of 'Sorry' ransomware attacks within China, utilizing the National Computer Virus Collaborative Analysis Platform. This particular ransomware, a novel variant that first surfaced in 2026, is crafted by attackers using the GO programming language and predominantly targets Linux-based Web servers that are accessible via the internet. Upon encrypting crucial user files, the ransomware appends the filenames with the '.sorry' extension. Concurrently, the attackers leave behind a ransom note instructing users to download an encrypted communication tool to contact them for the purpose of negotiating file ransom.

The ransomware capitalizes on authorization vulnerabilities within WebPros cPanel (identified by vulnerability IDs: CNNVD-202604-5641, CVE-2026-41940) to escalate its privileges to that of a server administrator. It is deployed and executed covertly, without the victim's knowledge, and masquerades as a regular sshd process to avoid detection. Following infection, the ransomware generates a unique identifier for the victim, incorporating details such as username, hostname, and CPU count, which is then relayed back to the attackers.

Additionally, the ransomware terminates pertinent services, including databases, security protections, and backups, and systematically pilfers business data, configuration files, and a variety of internal documents. It employs the AES encryption algorithm to encrypt user files, disrupting business systems and rendering critical data inaccessible. The AES decryption key is further secured through double encryption using the RSA algorithm. Moreover, the ransomware scans for SSH ports and endeavors to propagate laterally to other Linux hosts by exploiting weak passwords, showcasing its active propagation capabilities that could potentially lead to widespread infections within corporate intranets.

The National Computer Virus Emergency Response Center cautions that this ransomware is capable of operating and inflicting damage on the majority of mainstream Linux distribution operating systems prevalent in China (including innovative and trustworthy operating systems). Once infected, it may result in significant data breaches, destruction, and reputational harm to both enterprises and individuals. Presently, without the decryption key, there exists no dependable method to restore data that has been encrypted by this ransomware.

  • C114 Communication Network
  • Communication Home
7 X 24 Track global technological trends
Hot Topic