Business Support

Technical Support

About Guangxun

About Ainopol

Dual Attack of "Data Exfiltration + Encryption Ransom": How All-Optical Networks Stop the Sorry Ransomware from Spreading After Breach
2026-08-22 13:58:00 16

Dual Attack of "Data Exfiltration + Encryption Ransom": How All-Optical Networks Stop the Sorry Ransomware from Spreading After Breach

Ransomware is evolving.

Bai Jun, Member of the Cybersecurity Special Committee of the China Computer Federation and Vice President of Topsec Technologies Group, analyzed in a CCTV interview: “Whoever holds high-value data and cannot afford operational downtime becomes a target.” Manufacturing plants, financial institutions such as banks, healthcare, energy and internet enterprises are the prime targets, while small and medium-sized enterprises bear the brunt with the highest actual infection rates.

Ransomware has evolved from simple file encryption into a dual attack model of data exfiltration + encrypted extortion. Even with backups, data may have already been stolen. Attackers threaten to leak sensitive data unless ransom is paid. In the first half of 2026, global ransomware extortion cases rose 25% year-on-year to 4,544, with as many as 146 active ransomware gangs.

I. How Destructive Is the Dual Attack of the Sorry Ransomware?

First Attack Stage: Data Theft

The Sorry ransomware leverages the cPanel authorization vulnerability (CVE-2026-41940) to obtain server administrative privileges. After successful intrusion, it bulk-steals business data, configuration files and internal documents. Attackers exfiltrate data first and use it as leverage for extortion — threatening public disclosure if the ransom is not paid.

Second Attack Stage: Encryption for Ransom

Following data theft, the malware initiates encryption. It uses the AES algorithm to encrypt user files and further encrypts the AES decryption key via the RSA algorithm for double protection. Even if cybersecurity experts obtain the complete malware sample for line-by-line reverse engineering, the decryption key cannot be retrieved. Currently, there is no reliable way to restore encrypted data without the valid decryption key.

The fatality of this dual attack lies in the following:
Even with complete offline backups, sensitive data has already been stolen. Attackers do not necessarily demand payment for decryption; instead, they threaten to publish stolen data. For manufacturing factories, banks and medical institutions, public exposure of customer information, production formulas and patient medical records will result in losses far exceeding the ransom amount.

More dangerously, the malware features worm-like propagation and attempts to access other devices within the server intranet. A single compromised server may endanger the entire internal network.

II. Why Traditional Security Solutions Fail to Block Dual Attacks

Perimeter Firewalls: Effective for External Threats, Powerless Against Internal Lateral Movement

Once inside the intranet, the Sorry ransomware scans SSH ports and spreads laterally through weak passwords. Such east-west internal traffic is allowed by default by firewalls. A single breached server can lead to malware propagation across the entire data center within hours.

Endpoint Antivirus: Malware Disables Security Tools Before Encryption

Upon infiltration, the Sorry ransomware first terminates security protection and backup services. Traditional endpoint antivirus software is shut down before malware execution. Meanwhile, the malware disguises itself as the common sshd process, making detection difficult for signature-based solutions.

Lack of Network Segmentation: Mixed Core Data and General Business Traffic

Many enterprises deploy core business systems on the same network segment as office and guest networks. Once attackers compromise an office terminal, they gain direct access to core business servers, enabling unobstructed data theft and ransom encryption.

III. How All-Optical Networks Contain the Sorry Ransomware After Intrusion

AINOPOL adopts a core design philosophy: embed security as native capabilities of the all-optical network infrastructure, instead of deploying numerous independent security appliances in computer rooms as an afterthought.

To counter the dual attack of "data exfiltration + encrypted extortion", all-optical networks build a three-layer in-depth defense line, supplemented by additional auditing capabilities:

Layer 1: Gateway-level AV + IPS — Block Malware at the Perimeter
AINOPOL all-optical gateways natively integrate firewalls, AV antivirus engines, IPS intrusion prevention and other security capabilities into network hardware to deliver real-time threat scanning, behavior identification and attack blocking at the network boundary.

  • IPS Intrusion Prevention: Over 5,000 signature rules to intercept port scanning, vulnerability exploitation and abnormal activities in real time
  • AV Antivirus: A default signature library covering 4 million malware strains, supporting scanning of multiple file formats
  • WAF Application Protection: Mitigate SQL injection, XSS cross-site scripting and Webshell upload attacks

A single device delivers perimeter defense and ransomware interception. Any ransomware attempting to infiltrate the network will be blocked at the gateway.

Layer 2: Logical Business Domain Isolation + Micro-Segmentation — Halt Malware Lateral Propagation
After breaching the intranet, the "Sorry" ransomware seeks to access other devices for lateral movement. AINOPOL all-optical networks use VLAN logical isolation to divide office, production, R&D and guest environments into independent business domains with no inter-domain connectivity. Even if attackers take control of an office endpoint, they cannot reach production servers or core databases.

Layer 3: Passive All-Optical Architecture — Fewer Failure Points with High Reliability
All-optical networks deploy passive optical splitters to replace active aggregation switches, eliminating power supply requirements for equipment in wiring closets. The drastic reduction of active devices cuts the overall network failure rate by 95%. Fewer hardware nodes mean fewer potential breach entry points. In addition, fiber transmission is immune to electromagnetic interference, ensuring stable operation of core business systems during cyberattacks.

Layer 4: Full-Link Auditing — Enable Traceable Data Access Records
If attackers bypass the first two lines of defense and steal data, the all-optical network centrally collects and retains server access logs and terminal access records. Every access to core business systems is logged with clear records of user, timestamp and access source for post-incident forensics and traceability.

The modern dual ransomware attack model renders traditional passive enterprise defense ineffective and drastically raises risks of data leakage and business downtime. Leveraging native security capabilities built into the all-optical infrastructure, AINOPOL constructs a multi-dimensional in-depth defense system covering intrusion interception, intranet isolation, data encryption and end-to-end traceability. It effectively defends against evolving attacks from the Sorry ransomware and helps enterprises across industries safeguard data security and continuous production and operation.

FAQ

Q: What differentiates the dual "data exfiltration + encryption ransom" attack from conventional ransomware?
A: Traditional ransomware only encrypts files, and enterprises can restore data with available backups. Under the dual attack model, attackers steal data before encryption. Even with intact backups, data has already been exfiltrated, and attackers threaten public disclosure unless ransom is paid. Enterprises face escalated risks from system outages to complete sensitive data exposure.

Q: How does the Sorry ransomware achieve stealth intrusion?
A: It directly obtains server administrative privileges by exploiting the cPanel authorization vulnerability, requiring no user interaction such as clicking links or downloading attachments. After infiltration, it disguises itself as the common sshd process to evade detection by conventional security tools.

Q: What is the difference between gateway-level AV on all-optical networks and endpoint antivirus software?
A: Endpoint antivirus may be terminated before malware runs. Gateway-level AV is deployed at the network perimeter to detect malicious files before they enter the intranet. Signature databases are updated uniformly on gateways without maintenance on every individual endpoint.