国家计算机病毒应急处理中心日前发布预警,称境内发现多起"Sorry"勒索病毒攻击事件[1]。这是2026年新出现的勒索病毒家族[1],主要针对互联网暴露的Linux Web服务器[1]。该病毒通过利用WebPros cPanel授权问题漏洞(CNNVD-202604-5641,CVE-2026-41940)获取管理权限后实施攻击[1]。
病毒在感染系统后采用多层加密策略——使用AES算法对文件加密,再用RSA算法对解密密钥进行双重加密[1],被加密文件将被标记为原文件名加".sorry"后缀[1]。此外,该病毒具有内网横向传播能力,会通过扫描SSH端口22、2222、22222在企业内网中蔓延[1],可能造成企业内网大面积感染[1]。该病毒能在大部分主流Linux发行版及信创操作系统中运行[1]。
The National Computer Virus Emergency Response Center has issued a warning regarding multiple attacks by the "Sorry" ransomware, a newly emerged ransomware family discovered in 2026 [1]. The malware specifically targets Linux web servers exposed to the internet and exploits a WebPros cPanel authorization vulnerability (CNNVD-202604-5641, CVE-2026-41940) to gain administrative privileges before launching attacks [1].
Once deployed, the ransomware encrypts user files using AES encryption while employing dual-layer RSA encryption to protect decryption keys [1]. Infected files are marked with the ".sorry" suffix appended to their original names [1]. The threat poses a significant risk to enterprises due to the malware's lateral movement capabilities within networks—it actively scans for SSH access on ports 22, 2222, and 22222 [1]. This internal propagation ability could result in widespread infection across affected enterprise networks [1]. The ransomware is capable of running on most major Linux distributions as well as domestically developed operating systems [1].