Ransomware Tracker (Entry #338): Sorry Worm
ID: bc765f83-cc39-5224-a14d-7f834e8334b0
STIX ID: report--bc765f83-cc39-5224-a14d-7f834e8334b0
Feed Name: WatchGuard Secplicity Blog
Threat Score
On April 27, 2026 a Golang ransomware-worm dubbed **Sorry Worm** was observed on VirusTotal; it encrypts files (AES+RSA), appends the '.sorry' extension, and automatically exploits a widespread critical cPanel vulnerability (CVE-2026-41940) to achieve RCE and propagate across networks via embedded SSH brute-forcing and scanner toolkits—researchers produced multi-part analyses and victims were identified using the ransom note Tox ID and internet-wide search engines.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
