商务支持

技术支持

About Guangxun

关于光迅

National Virus Center Issues Urgent Alert for Stealth Intrusion by "Sorry" Ransomware: How All-Optical Networks Help Enterprises Maintain Continuous Operations
2026-08-22 14:03:21 18

National Virus Center Issues Urgent Alert for Stealth Intrusion by "Sorry" Ransomware: How All-Optical Networks Help Enterprises Maintain Continuous Operations

Recently, the National Computer Virus Emergency Response Center and the National Engineering Laboratory for Computer Virus Prevention jointly issued a security alert: multiple attacks involving the "Sorry" ransomware have been detected within China. The alert received special coverage on CCTV’s News Live Room on August 15.

This malware does not require users to click malicious links to trigger infection. It accesses servers directly by exploiting system vulnerabilities, with the intrusion remaining completely invisible to users. By the time an incident is discovered, data has already been encrypted.

As security experts note: whoever holds high-value data and cannot afford operational downtime becomes a target.

I. How Destructive Is the "Sorry" Ransomware?

Stealth Intrusion Without User Interaction

Most traditional ransomware relies on tricking users into clicking links, downloading attachments or granting installation permissions. The "Sorry" ransomware operates differently: it leverages an authorization vulnerability in WebPros cPanel to gain direct administrative access to servers. Attackers do not depend on employee missteps and can log into servers straight from the public internet.

Adding to its stealth, after deployment the malware disguises itself as the common sshd process, making detection difficult for conventional security tools.

Data Exfiltration First, Encryption Second, Followed by Ransom Demands

The "Sorry" ransomware executes attacks in six stages:

  1. Network Intrusion: Gain server administrative privileges via vulnerabilities and deploy malware silently
  2. Reconnaissance: Collect usernames, hostnames, CPU specifications, operating system information and transmit data to attackers
  3. Countermeasure Disabling: Terminate databases, security protection, backup and related services
  4. Data Theft: Bulk exfiltration of business data, configuration files and internal documents
  5. Data Encryption: Encrypt files with the AES algorithm, then encrypt the AES key using RSA — double encryption with no viable decryption workaround
  6. Intranet Propagation: Scan SSH ports and attempt lateral movement to other Linux hosts using weak passwords

Ransomware has evolved from simple file encryption into a dual attack model: data exfiltration + encrypted extortion. Even with intact backups, stolen data remains exposed; attackers threaten public disclosure of sensitive information unless ransom is paid.

Manufacturing Plants Are Prime Targets

Security experts confirm a clear targeting principle: “Whoever holds high-value data and cannot afford operational downtime becomes a target.” Manufacturing facilities, financial institutions including banks, healthcare providers, energy firms and internet enterprises face the highest risk. The reasoning is straightforward: these organizations manage high-value data and incur massive losses during service disruptions.

Small and medium-sized enterprises represent the most severely affected group. While individual ransom demands may be lower, SMEs generally maintain weaker defenses and make up a large target pool.

No Reliable Recovery After Infection

The "Sorry" ransomware uses a combined symmetric and asymmetric encryption scheme. It locally generates a random symmetric key to encrypt files, while the corresponding decryption private key is held exclusively by attackers. Even if cybersecurity professionals obtain the full malware sample for line-by-line reverse engineering, the decryption key cannot be recovered. Without a valid decryption key, there is currently no dependable method to restore encrypted data.

II. Why Conventional Security Solutions Fail

Perimeter Firewalls: Block External Threats but Cannot Stop Internal Lateral Spread

The "Sorry" ransomware accesses servers directly through vulnerabilities. Traditional firewalls are deployed at network boundaries and are largely blind to internal lateral movement after an initial breach. Once a server is compromised, the malware scans intranet SSH ports and spreads using weak credentials. Firewalls permit east-west internal traffic by default and do not intervene.

Antivirus Software: Malware Camouflaged as sshd Evades Legacy Detection

After deployment, the malware masquerades as the legitimate sshd process. Signature-based traditional antivirus tools struggle to identify this disguised threat. Furthermore, the ransomware first terminates security and backup services, disabling endpoint antivirus before the malicious payload fully executes.

Inadequate Log Auditing: Lateral Movement Cannot Be Traced

The "Sorry" ransomware can spread widely across corporate intranets. Legacy networks lack granular auditing for traffic between headless terminals and servers. Administrators often cannot identify the initial compromised endpoint or track which hosts were impacted during post-incident forensics.

III. How All-Optical Networks Secure Continuous Production Operations

The core design of AINOPOL’s integrated communication and encryption solution embeds security as native capabilities within the all-optical network infrastructure, rather than deploying discrete standalone security appliances in server rooms as an afterthought.

To counter the three major threats posed by the "Sorry" ransomware — stealth infiltration, lateral propagation and data theft — all-optical networks implement a four-layer in-depth defense framework:

Layer 1: Port-Based Access Control — Block Stealth Intrusion
For the "Sorry" ransomware to exploit vulnerabilities, attackers must locate exposed server management portals accessible over the public internet. AINOPOL all-optical networks enforce dual binding of ONU physical ports and MAC addresses. Every endpoint, including servers, undergoes identity verification at the moment of network access. Unauthorized devices cannot operate anonymously on the network, even if attackers obtain server administrative credentials.

Crucially, the AINOPOL solution supports remote management exclusively over encrypted SSL VPN tunnels, with no public-facing ports exposed. Server management consoles, remote maintenance interfaces and database administration ports are hidden from the internet, removing viable attack surfaces for threat actors.

Layer 2: Logical Business Domain Segmentation — Halt Lateral Malware Propagation
After breaching the intranet, the "Sorry" ransomware scans SSH ports and attempts to spread to additional Linux hosts via weak passwords. AINOPOL all-optical networks use VLAN logical segmentation to create isolated zones for office, production, R&D and guest networks with no inter-zone connectivity. Even if attackers compromise an office endpoint, they cannot reach production servers or R&D databases.

Native to the Dream Gateway M1 are microsegmentation, industrial traffic filtering, AI anomaly monitoring and multi-factor access controls. A single appliance rigidly isolates four security domains: office, production, R&D and IoT. Cross-domain lateral movement is blocked, eliminating the scenario where one compromised host endangers the entire network.

Layer 3: Native Gateway Security — Prevent Ransomware Infiltration and Propagation
AINOPOL all-optical gateways natively integrate firewalls, AV antivirus engines and IPS intrusion prevention systems within network hardware, delivering real-time threat scanning, behavioral analysis and attack mitigation at the network perimeter.

The AINOPOL M1 gateway features a full suite of built-in hardware security modules with no requirement for additional third-party security hardware. It delivers unified protection against DDoS flooding attacks, email and file-based ransomware, internal ARP attacks and cross-site data exfiltration. IPS and AV engines deployed on core network nodes detect port scanning, ransomware and trojan payloads in real time to block intrusion paths upfront. Any attempt by ransomware to spread laterally is intercepted at the gateway.

Ransom attacks have evolved beyond basic phishing tactics into a professional, industrialized threat landscape defined by vulnerability-driven stealth infiltration, combined data theft and encryption, and full-network lateral propagation. Legacy passive defenses can no longer address modern cybersecurity risks.

For enterprises reliant on uninterrupted production and valuable data assets, cybersecurity is no longer optional — it serves as the foundational safeguard for business continuity and digital assets. AINOPOL’s all-optical network integrated communication and encryption in-depth defense system eliminates the drawbacks of stacking separate security devices. Leveraging native security embedded in the network foundation, it closes attack vectors used by the "Sorry" ransomware across the full lifecycle: entry points, propagation paths, data protection and forensic auditing. The solution enables complete end-to-end security: proactive prevention before incidents, real-time blocking during breaches, and traceable investigation after attacks.

Facing continuously evolving cyber threats, enterprises must abandon passive defense strategies and deploy lightweight, unified, rigid underlying secure network architectures. This mitigates ransomware risks including production shutdowns, data leakage and financial losses, and reinforces the secure foundation for enterprise digital operations.

FAQ

Q: What differentiates the "Sorry" ransomware from conventional ransomware?
A: Its defining trait is stealth intrusion. Traditional ransomware requires users to click links, download attachments or approve installations. The "Sorry" variant accesses servers directly by exploiting system vulnerabilities without user interaction. Organizations often only discover the breach after data encryption is complete.

Q: Why are breaches still possible even with deployed firewalls?
A: Traditional perimeter firewalls block inbound threats originating from the internet. Once the "Sorry" ransomware enters the intranet, it scans SSH ports and spreads via weak passwords. Firewalls allow internal east-west traffic by default. All-optical networks resolve this architectural vulnerability through rigid business domain isolation to stop lateral movement.

Q: Can small and medium-sized enterprises with limited budgets deploy the all-optical network solution?
A: Yes. AINOPOL all-optical gateways natively integrate firewalls, AV antivirus engines and IPS intrusion prevention capabilities. No additional multiple security appliances are required. One device delivers perimeter defense, lateral isolation, data encryption and behavioral auditing, removing the need to deploy a suite of discrete hardware in server rooms.