Hosting providers and website owners using cPanel are facing a catastrophic ransomware campaign that has already encrypted thousands of Linux servers worldwide. The attackers behind the “Sorry” ransomware family have weaponized a critical zero-day vulnerability (CVE-2026-41940) to gain root access to WebHost Manager, deploy deeply embedded backdoors, and encrypt entire hosting environments—demanding ransoms through untraceable peer-to-peer networks.
The Victims: cPanel Hosting Environments Under Siege
Unlike traditional ransomware that targets individual workstations, the 2026 “.sorry” campaign focuses exclusively on Linux servers running cPanel and WHM—infrastructure that powers an estimated 70 million domains globally. When a single server is compromised, dozens or even hundreds of websites, databases, and customer portals are encrypted simultaneously.
Victims report catastrophic losses including:
- WordPress installations and theme configurations
- MySQL databases containing customer records and transaction histories
- Legacy media files (including irreplaceable SWF archives and proprietary imagery)
- Radio station control panels and streaming configurations
- E-commerce platforms with active shopping carts and order processing systems
All encrypted files are appended with the .sorry extension, transforming index.php into index.php.sorry and rendering entire websites inaccessible. A 404-byte ransom note named README.md is dropped in every affected directory.
How Attackers Breach cPanel Servers
The attack begins with exploitation of CVE-2026-41940, a critical authentication bypass vulnerability in cPanel’s session handling mechanism. The flaw allows unauthenticated remote attackers to achieve root administrative access without ever providing valid credentials.
Technical Attack Chain:
- CRLF Injection: Attackers send a malicious HTTP Basic authorization header containing raw Carriage Return Line Feed (
\r\n) characters. - Session File Poisoning: The cPanel daemon (
cpsrvd) writes unsanitized data to the session file, allowing injection of arbitrary key-value pairs. - Privilege Escalation: By injecting
user=root,hasroot=1, andtfa_verified=1, attackers promote their session to full root access—bypassing passwords and two-factor authentication. - SIEM Evasion: The exploit triggers a falsified log entry reading “FAILED LOGIN whostmgrd: user password incorrect,” making the breach invisible to administrators monitoring for successful logins.
Threat intelligence indicates active exploitation began as early as February 23, 2026—over two months before cPanel’s emergency patch on April 28, 2026. At disclosure time, Shodan identified approximately 1.5 million potentially vulnerable cPanel instances exposed to the internet.
Deep Persistence: Why Simple Patching Isn’t Enough
Once inside, the Sorry ransomware operators deploy a sophisticated, multi-layered persistence framework designed to survive reboots, patching, and even partial system restoration. Forensic analysis of compromised servers reveals the following backdoors installed within minutes of initial access:
- SSH Key Injection: Attacker-controlled ed25519 public keys appended to
/root/.ssh/authorized_keysfor password-less backdoor access. - Hidden SUID Binary: A 964 KB ELF binary dropped at
/usr/bin/.system_cache(note the leading dot hiding it fromlslistings). The Set-User-ID bit allows instant root privilege escalation from any user account. - Cron Job C2 Beacons: Daily callback scripts written to
/etc/cron.daily/cpanel_syncthat fetch updated payloads from command-and-control servers. - Bashrc Execution Hooks: Malicious droppers appended to
/root/.bashrc, ensuring re-infection every time an administrator logs in interactively.
This persistence model means that victims who simply apply the cPanel patch or restore encrypted files from backup without complete system sterilization will be re-compromised almost immediately.
The Ransom Demand: qTox and Operational Security
The 404-byte README.md ransom note represents a significant evolution in operational security. Unlike earlier variants that used centralized Telegram bots (which can be banned by platform administrators), the 2026 campaign demands victims download qTox—a peer-to-peer, end-to-end encrypted messaging application requiring no central servers.
Excerpt from the ransom note:
“Please contact us through the qtox tool Download qtox… If you can’t contact us, please contact some data recovery company(suggest taobao.com), may they can contact to us. Add our TOX ID and send an encrypted file and ‘Sorry-ID’ for testing decryption. Our TOX ID: 3D7889AEC00F2325E1A3FBC0ACA4E521670497F11E47FDE13EADE8FED3144B5EB56D6B198724”
The Tox protocol uses distributed hash tables (DHT) and peer-to-peer routing, making it virtually impossible for law enforcement to censor communications, seize domains, or trace attacker IP addresses. The note also suggests victims hire “data recovery companies” via Taobao.com—intermediaries who secretly negotiate with the gang and add massive markups to the ransom cost.
No Free Decryption: The Harsh Reality
Unlike the 2019 “Ims00rry” variant—which used weak AES-128 encryption that Emsisoft successfully cracked—the 2026 Linux campaign employs robust, unbreakable cryptographic standards. As of this writing, no public decryption utility exists for files encrypted with the .sorry extension.
Victims without secure, off-site, immutable backups face permanent data loss. The only guaranteed recovery method is complete system rebuild from bare metal, as attempting to manually clean a rooted server is forensically unsound.
CISA Directive and Mandatory Remediation
On April 30, 2026, CISA added CVE-2026-41940 to its Known Exploited Vulnerabilities catalog under Binding Operational Directive 22-01, mandating federal agencies to patch by May 3, 2026. Private sector organizations are strongly urged to follow the same timeline.
Required Actions for cPanel Administrators:
- Immediate Containment: Block external access to TCP ports 2083 (cPanel) and 2087 (WHM) at the firewall level.
- Sterilize Persistence Mechanisms: Audit
/root/.ssh/authorized_keys, hunt for hidden SUID binaries (find / -perm -4000 -type f), remove malicious cron jobs, and cleanse.bashrcfiles. - Emergency Patching: Execute
/scripts/upcp --forceto upgrade to safe versions (e.g., 11.136.0.5 or later across all release branches). - Immutable Backups: Implement autonomous snapshot systems like AWS FSx ONTAP’s ARP, which detects ransomware encryption patterns and generates recovery points milliseconds before encryption completes.
The Bigger Picture: Zero-Days for Profit
The 2026 “.sorry” campaign marks a watershed moment in ransomware evolution. Historically, zero-day exploits were the exclusive domain of nation-state actors focused on espionage. Financially motivated ransomware groups relied on phishing, weak RDP credentials, or long-unpatched N-day vulnerabilities.
This campaign demonstrates definitively that cybercriminal syndicates now possess the capital, R&D resources, and technical sophistication to discover, stockpile, and weaponize zero-day vulnerabilities at scale against global infrastructure. The shift from targeting individual Windows endpoints to dominating Linux enterprise servers reflects ruthless optimization: one compromised cPanel instance paralyzes hundreds of websites simultaneously, maximizing leverage and forcing faster ransom payouts.
For hosting providers and website owners, the lesson is unforgiving: internet-facing control panels are the new frontline. Patch management measured in weeks is no longer acceptable—remediation SLAs must be measured in hours. And without immutable, offline backups, you are playing Russian roulette with your entire business.