Skip to main content

Server Files Encrypted with .sorry Extension and WHM Internal Error

Comments

2 comments

  • Pozitifdenge

    This is unfortunately the biggest cPanel security breach in history. Two of our servers were compromised in the same way. First, we reverted to a snapshot taken two days prior and tried to update cPanel to patch the vulnerability, but as many people have written on this platform, unfortunately, the cPanel update failed (I believe this problem is cPanel-related) and the vulnerability persisted.

    We closed the WHM/cPanel ports on the compromised server and transferred website backups via SSH to another clean server (a server not using cPanel). Because we had installed the snapshot, the sites were in their state before the server was hacked. We formatted the compromised server, reinstalled the operating system and cPanel, and then restored the backups we transferred to the other server.

    NOTE: Be aware that if you are installing the operating system and cPanel from your datacenter images, the cPanel version included in those images may still be an older version containing security vulnerabilities. In this situation, the moment you reinstall your server, you get hacked again. The bots are so numerous and work so fast that you get hacked again before you can even update cPanel after the fresh installation.

    In conclusion, cPanel truly failed miserably in this serious hacking attempt. Furthermore, it shows that this vulnerability has been exploited since February, but instead of damaging the servers, the hackers seized and backed up the data on them. After the security vulnerability was revealed, the hackers started encrypting the data on the servers and demanding a ransom in cryptocurrency (.sorry extension).

    0
  • cPRex Jurassic Moderator

    sercandemir - as you've likely seen, this was caused by the following exploit:

    https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026

    I'll go through and answer your questions individually to ensure nothing is missed:

    Q1 - Is there a known recover path for the .sorry extension ransomware on cPanel environment?
    A1 - As with any root compromise, the only safe action is to create a new server and restore the data from backups.

    Q2 - How can I restore the integrity of the cPanel/WHM binary files and plugins to at least regain access to the interface?
    A2 - There is likely not going to be a way to do this with the server in its current state.

    Q3 - What are the recommended steps to investigate the entry point of this breach?
    A3 - There is little point in investigating as the source is well known by now.  Also, since the server's disk is already encrypted with the .sorry malware, the actual entry point would be hidden.

    I'm sorry I don't have better news but if you'd like to create a support ticket with our team, assuming root access to the SSH service still works, we can take a look at the server and confirm these things for you.

    0

Please sign in to leave a comment.