logo

Ransomware Tracker (Entry #338): Sorry Worm

ID: bc765f83-cc39-5224-a14d-7f834e8334b0

STIX ID: report--bc765f83-cc39-5224-a14d-7f834e8334b0

Feed Name: WatchGuard Secplicity Blog

Threat Score
80/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Ryan Estes

...
...

On April 27, 2026 a Golang ransomware-worm dubbed **Sorry Worm** was observed on VirusTotal; it encrypts files (AES+RSA), appends the '.sorry' extension, and automatically exploits a widespread critical cPanel vulnerability (CVE-2026-41940) to achieve RCE and propagate across networks via embedded SSH brute-forcing and scanner toolkits—researchers produced multi-part analyses and victims were identified using the ransom note Tox ID and internet-wide search engines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.