
In August 2026, the National Computer Virus Emergency Response Center and the National Engineering Laboratory for Computer Virus Prevention and Control jointly issued a security alert, confirming multiple "Sorry" ransomware infection cases across China. CCTV’s News Live subsequently ran a special news report on the threat.
Unlike conventional malware, this ransomware logs into servers directly by exploiting system vulnerabilities, with zero user‑visible signs of intrusion. Victims do not need to click malicious links or download malicious attachments to get compromised.
Manufacturing facilities are its primary targets, for a simple reason: production lines cannot afford downtime, and industrial data carries high commercial value.
Of greater concern is its robust lateral‑movement capability within internal networks. Once an office PC is compromised, the malware spreads laterally: scanning other devices, attempting weak‑password logins, and hunting for gateways to production systems. Without segmentation between office and production networks, "Sorry" ransomware can take over an entire factory starting from a single endpoint in merely tens of minutes.
Written in Go, "Sorry" ransomware primarily targets internet‑facing Linux web servers. It leverages the WebPros cPanel authorization flaw CVE‑2026‑41940 to obtain administrative privileges, deploying and executing payloads without any awareness from system operators.
After infiltration, the malware disguises itself as a legitimate sshd process, making detection extremely difficult for traditional security tools. By the time administrators spot anomalies, data has already been encrypted.
Ransomware has evolved beyond simple file‑locking into a dual‑threat model: data theft combined with cryptographic extortion. After breaching a host, "Sorry" first mass‑exfiltrates business records, configuration files and internal documents. It then encrypts local files with the AES algorithm, while encrypting AES decryption keys with RSA for double‑layer protection.
Experts from the China Computer Federation note that even with full malware samples for reverse‑engineering, security teams cannot recover decryption keys. At present, there exists no reliable method to restore the encrypted data.
This represents its most destructive capability. The ransomware actively scans internal SSH ports and spreads to additional Linux hosts by exploiting weak passwords. Obfuscated variants feature over 99 % symbol mangling, equipped with automated SSH lateral movement and hybrid encryption, posing severe risks to on‑premises server clusters.
Without isolation barriers between office IT and production OT networks, the malware can jump from office workstations straight to PLC controllers, MES servers and shop‑floor industrial PCs. An entire factory’s production infrastructure can be locked down within tens of minutes.
As stated by experts from the China Computer Federation Technical Committee on Computer Security: “Whoever holds high‑value data and cannot tolerate operational shutdown becomes a target.”
High‑risk sectors include manufacturing plants, financial institutions such as banks, healthcare, energy and internet enterprises. Small‑and‑medium‑sized enterprises with limited security budgets yet large volumes of valuable data suffer the highest real‑world infection rates.
In H1 2026, global reported ransomware extortion incidents rose 25 % year‑on‑year to 4,544 cases, with 146 active ransomware gangs operating worldwide.
The AINOPOL Dream Gateway (M1) natively integrates three security engines: Intrusion‑Prevention System (IPS), Anti‑Virus (AV), and Threat‑Intelligence Analytics, establishing the first line of perimeter defence to keep threats out.
IPS Intrusion‑Prevention: Block exploit attempts at the network boundary
The IPS engine carries more than 10,000 predefined rules covering 26 exploit categories. It identifies and blocks CVE‑2026‑41940 cPanel‑based intrusion attempts from the "Sorry" ransomware before malicious traffic enters the local network. Both local and online signature‑database updates maintain up‑to‑date protection.
AV Anti‑Virus: Scan and neutralize malware before entry
Powered by a 4‑million‑signature virus database, the AV engine performs deep inspection across multiple file formats. Full‑traffic scanning covers email attachments, web downloads and intranet file transfers. Malicious payloads are eliminated at the gateway, never reaching backend servers.
Threat‑Intelligence Analytics: Instantly neutralize phishing domains and C2 servers
Supporting built‑in and third‑party threat feeds, this module blocks malicious IP addresses, phishing domains and command‑and‑control (C2) hosts in real time. After infection, "Sorry" ransomware contacts C2 servers to receive encryption instructions. The gateway cuts off these outbound connections within milliseconds, breaking a critical link in the ransomware kill‑chain. Newly activated C2 servers and phishing domains can also be rapidly identified and blocked.
The three engines operate in concert to form a closed‑loop perimeter defence:
VLAN logical isolation: Segregate business domains to prevent cross‑domain breach
For multi‑service workloads running over shared fibre infrastructure, the AINOPOL solution uses hardened VLAN segmentation to create independent security domains for production, office staff, guest access and video surveillance. Each domain operates in complete isolation.
Even if the office network is compromised, threat actors cannot discover PLC IP addresses or reach MES servers within the production zone — segmentation removes visibility of production assets for the malware. Coupled with granular QoS policies, production control traffic and remote conference streams receive priority bandwidth; bulk office downloads cannot starve real‑time industrial control flows.
Ransomware threats are hard to foresee, and post‑attack decryption is often impossible. Proactive network segmentation plus robust perimeter security constitute the core mitigation strategy. Leveraging the AINOPOL all‑optical architecture and native security capabilities of the Dream Gateway M1, enterprises can enforce hardened IT‑OT separation, eliminate malware lateral‑propagation pathways at source, defend against stealth "Sorry" ransomware intrusions, and guarantee continuous operations for factories and enterprise campuses.
Q: What differentiates "Sorry" ransomware from ordinary ransomware?
A: Its defining traits are stealth zero‑click intrusion and aggressive lateral spread. It compromises servers by exploiting vulnerabilities with no requirement for end‑user clicks. Post‑infection, it automatically scans internal SSH ports and propagates via weak‑password credentials. Full‑factory compromise originating from one infected host can unfold in tens of minutes.
Q: Why are manufacturing plants primary targets?
A: As cited by China Computer Federation experts during a CCTV interview: “Whoever holds high‑value data and cannot tolerate operational shutdown becomes a target.” Manufacturing plants face massive financial losses from production halts, while process‑technology datasets represent extremely valuable intellectual property.