Sorry Ransomware Exploits cPanel Vulnerability to Directly Lock Linux Servers in Multiple Chinese Incidents
China's National Computer Virus Emergency Response Center has issued an alert after multiple real-world incidents involving the Sorry ransomware. The malware reaches internet-facing Linux web servers through a cPanel authorization vulnerability (CNNVD-202604-5641, CVE-2026-41940) and operates without any phishing emails or user mistakes.
Last Friday at 10:30 p.m., an ERP implementation specialist received an urgent call from a manufacturing client whose entire business system had become inaccessible. Every file now carried the .sorry extension, and a ransom note instructed victims to download an encrypted messaging tool to negotiate payment. On-site inspection revealed stopped databases, killed backup services, and fully encrypted website files, all achieved without any visible signs of compromise.
Attack vector and stealth techniques
Unlike typical ransomware that relies on email attachments, Sorry is written in Go and directly exploits a cPanel flaw to obtain server management rights. Once inside, the malware masquerades as the standard sshd process, making detection difficult for system administrators. The same binary runs on most mainstream Linux distributions, including domestic Xinchuang operating systems now being deployed in government, finance, energy, and healthcare sectors.
Six-stage attack chain
- Network intrusion: Silent deployment via the cPanel vulnerability and process masquerading.
- Environment reconnaissance: Collection of username, hostname, CPU count, OS version, and network interfaces sent back to the attackers.
- Obstacle removal: Termination of database, security, and backup services.
- Data theft: Exfiltration of business data and documents for potential double extortion.
- Encryption: AES encryption of files followed by RSA protection of the AES key; all files receive the .sorry suffix.
- Lateral movement: Scanning of ports 22, 2222, and 22222 for weak SSH passwords to spread across the internal network.
Small and medium-sized enterprises remain the primary targets because they often expose cPanel panels directly to the internet, reuse weak passwords, and lack offline backups. The center recommends immediate version checks and updates for cPanel, WHM, and WP Squared, strict network exposure reduction through VPNs or bastion hosts, strong unique credentials, up-to-date Linux antivirus with real-time monitoring, truly offline backups, and verification of suspicious files via the national analysis platform before execution.
Related articles
ShinyHunters Claims Breach of FBI Recruitment Portal and Demands Eight-Figure Ransom
The hacker group ShinyHunters has publicly claimed responsibility for compromising the FBI's official recruitment website, FBIjobs.gov, asserting access to sensitive data belonging to nearly all FBI agents as well as job applicants. According to the group, the intrusion extended to multiple internal systems including criminal justice databases, human resources platforms, and Medlink. The attackers stated they exploited a zero-day vulnerability in Oracle PeopleSoft to achieve remote code execution and subsequently defaced the careers site with a fabricated seizure notice. The FBI has acknowledged awareness of unauthorized activity on the portal but has not confirmed any data theft or the scope of the intrusion. ShinyHunters is now demanding an eight-figure ransom payment, framing the amount as a minor fraction of its own resources and warning that time is limited. The operation appears to be retaliation for an FBI public statement issued in May regarding the group's prior activities. Independent verification of the claims remains unavailable, and experts note that extortion groups routinely exaggerate the value of stolen data to increase pressure on victims.
PAYLOAD Ransomware Seizes Active Directory GPO to Disrupt Entire Windows Domain Without Encryption
Researchers at Kaspersky have documented an attack by the PAYLOAD ransomware that paralyzes an entire Windows domain without encrypting a single file. Instead of encryption, the operators leverage native Windows policy mechanisms to enforce disruption across the environment. The core of the attack is a malicious Group Policy Object named PAYLOAD linked directly to the root of the Active Directory domain. This placement allows the policy to reach virtually every connected device, turning it into a corporate-wide disruption tool. Through the GPO, the group distributes ransom notes from SYSVOL, replaces wallpapers and lock screens with extortion images displaying the message Welcome to Payload, and disables local administrator accounts on affected machines. A second policy object named win Firewall Off disables the Windows firewall across the entire fleet, increasing exposure during the operation. Initial access occurred in April 2026 via a compromised legitimate domain account on a FortiGate SSL VPN, with possible entry vectors including phishing, password spraying, and credential stuffing. The victim is a manufacturing company in the Middle East. The extortion model combines data theft with operational shutdown, delivering effects similar to traditional ransomware but without any decryption key to negotiate.
Ransomware Operators Hijack Active Directory via GPO to Lock Companies Without Encryption
Kaspersky researchers have uncovered a new extortion campaign called Payload that targets manufacturing companies by compromising privileged accounts and seizing control of Active Directory. Instead of deploying traditional ransomware encryptors, the attackers created a Group Policy Object named Payload linked to the domain root. This GPO automatically changed desktop wallpapers and lock screens across all systems, displayed ransom demands, and disabled administrative accounts after policy refresh. The group also exfiltrated valuable corporate data before the lockdown and later published it on the dark web to increase pressure on victims. Because the attack relied entirely on legitimate Windows mechanisms such as VPN access and Group Policy, conventional antivirus solutions proved ineffective. Experts recommend monitoring GPO changes, enforcing phishing-resistant MFA on VPN and admin systems, and applying least-privilege principles to limit the impact of credential compromise.
SETTRA Ransomware Deploys MeshAgent and gdrv.sys BYOVD Against Windows Systems
Huntress analysts have identified two separate incidents involving the newly observed SETTRA ransomware targeting Windows environments. The attacks combined the legitimate MeshAgent remote management tool with a Bring Your Own Vulnerable Driver technique using gdrv.sys to disable security controls. Victims included a consumer services and retail company hit in July and an industrial organization compromised in September. Initial access occurred through VPN connections or previously stolen credentials, after which operators deployed MeshAgent to maintain persistence and execute commands. Before encryption, the group deleted Windows event logs, disabled system recovery features, removed recovery partitions, and overwrote free disk space. Encrypted files received the .locked or .locked_wip extensions, with the ransomware binary named after the victim domain and ransom notes dropped as RESTORE_FILES.txt.