Business Support

Technical Support

About Guangxun

About Ainopol

The "Sorry" Ransomware Keeps Spreading: How Enterprise‑Campus All‑Optical‑Networks Build Firewalls for IT/OT Isolation
2026-09-05 19:20:26 3

The "Sorry" Ransomware Keeps Spreading: How Enterprise‑Campus All‑Optical‑Networks Build Firewalls for IT/OT Isolation

Servers get locked without warning. Data is exfiltrated before encryption. Enterprises are the primary targets.

The IT‑security community has been on edge lately.

A ransomware strain dubbed “Sorry” is carrying out frequent attacks across China. The National Computer Virus Emergency Response Center and the National Engineering Laboratory for Computer Virus Prevention and Control have jointly issued a security alert.

What makes it even more alarming is that this malware can breach servers stealthily without tricking users into clicking any links.

Intrusion, data theft, encryption, ransom demand — the whole process unfolds undetected. By the time victims notice, all files have been renamed with the “.sorry” extension.

This is not science fiction; it is real‑world incidents taking place across China.

What Makes the "Sorry" Ransomware So Unscrupulous?

Most ransomware follows a familiar playbook: phishing emails trick employees into opening malicious attachments, which encrypt files on office endpoints.

Sorry operates on an entirely different attack vector.

Written in Go language, it targets Linux Web servers exposed to the public internet. Its attack vector exploits a cPanel authorization vulnerability documented as CVE‑2026‑41940, boasting a CVSS severity score of 9.8. As one of the world’s most widely used web‑hosting control panels, cPanel is adopted by countless small‑and‑medium‑enterprises to manage their web servers.

Attackers exploit this vulnerability to obtain full server administrative privileges, deploying and executing ransomware without any user awareness.

Adding to its stealth, the malware disguises itself as the legitimate sshd process. Linux administrators know that sshd is the standard remote‑management daemon running on every server. Operators will hardly raise suspicion when spotting it in process lists.

By the time abnormal behaviour is detected, irreversible damage has already occurred.

How the Sorry Ransomware Executes Attacks

Unlike conventional malware that relies on social‑engineering lures, the Sorry ransomware skips that step entirely. It runs a complete, streamlined attack chain from initial compromise to data encryption:

  1. Network Intrusion: Exploits the cPanel vulnerability to seize server privileges, silently implants malware and masquerades as the sshd process.
  2. Environment Profiling: Generates a unique identifier, collects and exfiltrates system metadata including usernames, hostnames, CPU core counts and operating‑system versions.
  3. Obstacle Elimination: Actively terminates database services, security‑protection software and system‑backup services. Backups are destroyed before encryption to eliminate recovery options.
  4. Data Exfiltration: Bulk‑packages business data, configuration files and internal documents for covert outward transmission. Even if offline backups enable file restoration, attackers retain stolen datasets — a classic double‑extortion ransom‑tactic.
  5. Data Encryption: Encrypts files via the AES algorithm, then encrypts AES keys with RSA. All compromised files receive the unified “.sorry” filename suffix. No reliable data‑recovery method exists without the attacker’s private key.
  6. Intranet Propagation: Scans internal networks for SSH ports such as 22, 2222 and 22222, performing brute‑force attacks against weak passwords for lateral movement across additional Linux hosts. One compromised device may trigger cascading intranet‑wide infections.

Who Are the Primary Targets?

According to cybersecurity experts, the Sorry ransomware prioritises enterprises handling large‑volume data where business downtime incurs heavy costs. Manufacturing plants, financial institutions, healthcare facilities, energy operators and internet‑service firms face the highest risk.

Although ransom‑demands for small‑and‑medium‑enterprises are relatively low, SMEs suffer the highest infection rates due to vast market footprint and generally inadequate security postures.

Notably, this ransomware runs on most mainstream domestic Linux distributions, including domestic‑innovation operating systems. Accelerated domestic‑IT‑substitution initiatives within government, finance, energy and healthcare sectors render these servers fresh targets for ransomware gangs.

Why Traditional Defences Fail to Block It

Many organisations assume “having a firewall in place equals security”. Yet Sorry ransomware exploits inherent weaknesses in legacy‑security architectures:

  • Weak detection for emerging threats at perimeter defences: Outdated firewall rules deliver limited capability to identify new ransomware variants and zero‑day‑exploit activity. By the time anomalies surface, malicious payloads have already spread throughout internal networks.
  • Uncontrolled lateral intranet traffic: Traditional firewalls reside at network egress points and only filter traffic crossing between the internet and local‑area‑networks. Once malware bypasses perimeters via phishing or compromised business nodes, host‑to‑host lateral traffic never traverses boundary firewalls. Boundary hardware cannot observe or block intranet scanning, exploit attempts and infiltration activity. By the time business disruption is noticed, malware has established multiple footholds inside the network.
  • Absence of effective intranet segmentation enables unrestricted lateral movement: Numerous factories and industrial campuses maintain flat‑network architectures without logical security‑domain isolation. IT office networks, business servers and OT production‑floor networks are interconnected with no access‑control boundaries. Compromise of any single intranet node enables attackers to pivot freely across the network via weak passwords, credential reuse and SSH access. Threat actors can advance from office zones all the way to core production equipment; one breach creates enterprise‑wide risk.

How All‑Optical‑Networks Build IT/OT Isolation Firewalls

Against Sorry’s end‑to‑end attack chain of “intrusion‑exfiltration‑encryption‑propagation”, and given gaps in legacy security that focus merely on perimeter protection while ignoring lateral‑traffic risks and missing network segmentation, enterprises must rethink security from the network‑architecture perspective.

AINOPOL’s integrated “communication‑and‑security converged” all‑optical‑solution avoids reactive post‑infection mitigation. Instead, it embeds security capabilities deep within enterprise‑campus network infrastructure. Built upon an all‑optical communication foundation, security controls are embedded within network boundaries, business‑zone partitions and production‑network environments to deliver a five‑layer in‑depth‑defence framework.

  1. Physical‑Environmental Layer: Consolidate hardware foundations
    Focuses on equipment‑rooms, cabling and physical hardware. Access‑control management, video surveillance and fibre‑optic‑eavesdropping‑detection deliver hard‑physical safeguards. Leveraging physical controls and optical‑network properties, it defends hardware assets against tampering and unauthorised access to establish a trusted physical baseline for the entire system.
  2. Communication‑Network Layer: Secure data transmission
    Guarantees link‑level and payload‑security. Link encryption, network slicing isolation and integrity‑verification mechanisms are implemented. Built‑in PON encryption and hardware‑level slicing preserve confidentiality and integrity for in‑flight data, preventing eavesdropping and tampering and forming secure communication pipelines interconnecting all network nodes.
  3. Perimeter‑Boundary Layer: Secure network entry points
    For internal‑external network boundaries, the M1 Dream Gateway is deployed, integrating Next‑Generation Firewall (NGFW), Intrusion‑Prevention System (IPS) and Web‑Application‑Firewall (WAF). It delivers robust filtering to block external infiltration attempts while governing outbound internal‑network access, acting as the primary access‑gatekeeper for the defence system.
  4. Computational‑Environment Layer: Reinforce business‑oriented safeguards
    Targeting endpoints and business‑application environments, this layer enforces identity‑based admission control, anti‑malware protection, patch‑management and operation‑audit logging. A unified endpoint‑security framework ensures user‑activity and business‑runtime environments remain resilient against compromise and abuse, forming core safeguards adjacent to production workloads.
  5. Management‑Orchestration Layer: Centralised global governance
    Delivers enterprise‑wide unified oversight through log retention, security‑situation‑awareness and coordinated‑policy orchestration. Supported by the EAAS cloud‑management platform, it aggregates security telemetry from all defence layers, visualises enterprise‑wide risk exposure and enables coordinated policy scheduling, functioning as the central “command hub” of the security system.

The core principle of this five‑tiered defence lies in “layered safeguards with cross‑validation”. Even if one defensive tier is breached, subsequent layers contain lateral‑attack movement.

Legacy single‑firewall architectures suffer full‑system compromise once perimeters are bypassed. In‑depth‑defence distributes trust‑validation across multiple checkpoints, drastically raising attackers’ operational costs.

The communication‑security‑converged architecture maps these five defensive tiers onto tangible network‑and‑security hardware, translating Cybersecurity Class‑2 compliance requirements into deployable, verifiable engineering deliverables.

The spread of the “Sorry” ransomware sends another urgent warning: amid deep IT‑OT convergence, traditional perimeter‑only “gate‑guarding” security strategies are no longer sufficient. Enterprises require holistic security networks spanning from the physical layer up to the application layer — capable of risk isolation, native encryption and intelligent threat mitigation. AINOPOL’s integrated “communication‑and‑security converged” all‑optical‑solution constitutes critical defensive countermeasure against such threats.

Do not wait until files get encrypted and production lines grind to a halt before recognising the value of network isolation.