Ransomware - Sorry Worm

Sorry Worm
Aliases
Sorry
Sorry 2026
SorryGo
Description

On April 27, 2026, a ransomware written in Golang was submitted to VirusTotal that appended the '.sorry' string to the encrypted filenames. Upon initial review, this was not the same as the 2018 Sorry ransomware, which was built using the open-source HiddenTear encryptor. This was novel, and that submission is the first-ever appearance of the Sorry Worm ransomware in the wild.

The very next day, cPanel released a Security Update addressing a new critical vulnerability that affected almost all versions of cPanel and WebHost Manager/WordPress Squared, which allowed remote code execution if unpatched and exploited. Over the next few days, they provided updates, articles, detection scripts, and patches for immediate remediation. However, on April 29, two days after the Sorry Worm appeared and a day after cPanel's update, watchTowr Labs published an extensive report (The Internet Is Falling Down, Falling Down, Falling Down) walking through the software's affected components, vulnerability anatomy, and exploit details. If you wanted a quick overview of this cPanel vulnerability, cPanel's Security Update and watchTowr's report are more than sufficient. More information exists on the official CVE page: CVE-2026-41940.

The relationship between the Sorry Worm and CVE-2026-41940 is that the Sorry Worm automatically exploits the vulnerability, encrypts files, and propagates across networks, all in a single package. To better understand how the Sorry Worm works, independent threat researcher(s) from OHIIHO Research produced a three-part, detailed breakdown on how they discovered the ransomware-worm hybrid (part 1), the malware's internals (part 2), and similar campaigns and how to defend against these threats (part 3). According to the researcher(s), they discovered the worm by monitoring open-source sandboxes such as VirusTotal and Hatching Triage. They quickly learned that the same malware appeared on other networks several hours after the initial infection, and they also highlighted a bundled SSH-bruteforcing backdoor toolkit embedded within it. Additionally, a Marai-like SSH scanner kit was included in the file analysis. All three of these behaviors are indicative of worm-like activity.

Thus, we have a novel ransomware written in Golang that can encrypt files (using AES+RSA), append the '.sorry' extension, exploit a critical vulnerability affecting a large number of web servers, and worm through networks by brute-forcing SSH relays, all in one package. Since these affect web servers, we were able to search for possible victims of this attack using a few open-source methods, primarily by googling the Tox ID in the ransom note (literally) and using Shodan/Censys to do the same. The ransom notes and victims listed in the entry are from those efforts.

Ransomware Type
Crypto-Ransomware
First Seen
Extortion Types
Direct Extortion
Website Defacing
Communication
Medium
Identifier
Tox
Encryption
Type
Hybrid
Files
AES-CBC
Key
RSA-2048
File Extensions
Type
File Extension
Append
.sorry
Ransom Note Name
README.md
Samples (SHA-256)
2fc0a056fd4eff5d31d06c103af3298d711f33dbcd5d122cae30b571ac511e5a
42a1aded85892a80c83f741a7ac00e7e75015166c3be0bae29d93d3a4714711d
Industry Sector Country Extortion Date Amount (USD)
Music & Entertainment Ecuador
Energy Bangladesh
Engineering Services United Arab Emirates
Private Capital Nigeria
Charity & Nonprofits North Macedonia
Forestry & Lumber United States
Education India
Automotive India
Music & Entertainment Brazil
Retail & Wholesale Peru
Legal United States
Architectural Services United Arab Emirates
Fashion & Textiles Türkiye
Healthcare & Medicine Indonesia
Information Technology India
Beauty & Cosmetology India
Oil & Gas Somalia
Government Kenya
Paper & Printing Bangladesh
Healthcare & Medicine India
Healthcare & Medicine United States
Media & Marketing United States
Education Bangladesh
Media & Marketing United States
Healthcare & Medicine Peru
Healthcare & Medicine Nigeria
Media & Marketing United States
Private Capital United States
Hospitality & Leisure United Kingdom
Information Technology United States
Hospitality & Leisure India
Hospitality & Leisure Nigeria
Individual Unknown
Environmental Services Nigeria
Healthcare & Medicine Bulgaria
Electronics & Robotics United Kingdom
Security & Cybersecurity India
Education Canada
Media & Marketing United States
Unknown Unknown
Education India
Government Saudi Arabia
Unknown Unknown
Healthcare & Medicine Tanzania
Media & Marketing Colombia
Manufacturing Peru
Conglomerate Nigeria
Media & Marketing United States
Engineering Services Bangladesh
Healthcare & Medicine Brazil
Construction & Home Improvement United States
Construction & Home Improvement United Arab Emirates
IT Consulting Hungary
Charity & Nonprofits Nigeria
Retail & Wholesale United States
Environmental Services Australia
Media & Marketing United States
Media & Marketing India
Professional Services United Arab Emirates
Manufacturing India
Media & Marketing United States
Information Technology Nigeria
Electronics & Robotics Myanmar
Charity & Nonprofits Brazil
Individual Brazil
Architectural Services Malaysia
Food & Beverage United Kingdom
Manufacturing Malaysia
Sports & Gaming Israel
Construction & Home Improvement United Kingdom
Charity & Nonprofits Pakistan
Information Technology United States
Media & Marketing United States
Sports & Gaming Egypt
Beauty & Cosmetology Taiwan
Food & Beverage Costa Rica
Energy United States
Media & Marketing Nigeria
Charity & Nonprofits Nigeria
Education Nepal
Furnishing Romania
Information Technology Unknown
Food & Beverage Bangladesh
Maritime Spain
Fashion & Textiles Nigeria
Security & Cybersecurity France
Hospitality & Leisure Jamaica
Automotive Germany
Media & Marketing India
Human Resources & Staffing Kenya
Media & Marketing India
Hospitality & Leisure Bangladesh
Healthcare & Medicine Pakistan
Automotive United States
Food & Beverage United Kingdom
IT Consulting Pakistan
Manufacturing India
IT Consulting Nigeria
Construction & Home Improvement Bangladesh
Legal Nigeria
Unknown Unknown
Private Capital United States
Information Technology Unknown
Oil & Gas Malaysia
Professional Services Bulgaria
Information Technology United States
Information Technology Indonesia
Hospitality & Leisure Iran
Utilities Georgia
Charity & Nonprofits Somalia
Education India
Unknown Unknown
Oil & Gas Georgia
Information Technology Pakistan
Automotive Hungary
Charity & Nonprofits United States
Religion United States
Information Technology India
Information Technology Netherlands
Legal United States
Media & Marketing United States
Healthcare & Medicine Nigeria
Architectural Services Nigeria
Hospitality & Leisure United States
Charity & Nonprofits Trinidad and Tobago
Heavy Equipment & Machinery United States
Heavy Equipment & Machinery United States
Furnishing United States
Beauty & Cosmetology United States
Professional Services Brazil
Charity & Nonprofits Somalia
Transportation, Distribution & Logistics India
Charity & Nonprofits Somalia
Hospitality & Leisure United Kingdom
Information Technology Peru
Media & Marketing United Kingdom
Information Technology Romania