.sorry / .mkp Ransomware Decryption: Don't Rush to Pay the Ransom
Cybersecurity 2026-10-08 CentralComputer Team

.sorry / .mkp Ransomware Decryption: Don't Rush to Pay the Ransom

.sorry / .mkp Ransomware Decryption: Don't Rush to Pay the Ransom

.sorry / .mkp Ransomware Decryption: Don't Rush to Pay the Ransom

One Friday afternoon in August, a wholesaler in Sham Shui Po called us, voice urgent: "All our files turned .sorry. The ransom note says if we don't pay 0.3 BTC within 48 hours they'll delete the decryption keys. Should we just pay?" I stopped him immediately: "Hold on! Don't touch your wallet yet — hear me out first."

Typical reaction. .sorry and .mkp excel at using "deadlines" to pressure you. The name .sorry is cheeky enough — criminals saying sorry while asking for money. Here's why you shouldn't rush.

The .sorry / .mkp psychological game

These variants aren't the most technically advanced (standard AES-256), but their "marketing" is slick:

  • Countdown timers: Ransom notes include a timer (some dynamic HTML, some just "48 hours"), creating urgency. Psychologically, people make poor decisions under time pressure — criminals know this.
  • The "sorry" hypocrisy: .sorry notes often open with "Sorry about that!" or "We are sorry to inform you..." — as if they didn't want to do it, lowering your hostility so "paying to solve it" feels reasonable.
  • .mkp loves shared folders: .mkp particularly targets network shared folders. SMEs often run whole departments on one shared folder — one hit stops everyone, maximising pressure.
  • Tiered pricing: "0.3 BTC within 48 hours, 0.6 after" — making you feel "pay early, save money". Really it's rushing you past clear thinking.

The Sham Shui Po boss nearly fell for it. "I thought, short pain beats long pain — just pay and be done." Luckily he called us first.

Why not rush? Three harsh truths

Truth 1: Payment doesn't guarantee recovery

Tracking .sorry/.mkp cases where ransoms were paid:

  • ~60%: Got a decryptor, recovered most files (but not all — some corrupt)
  • ~20%: Got a decryptor that didn't work / corrupted everything
  • ~20%: Paid, criminals vanished

So your HK$150,000 has a 40% chance of going down the drain. Still feel like "short pain"?

Truth 2: The decryptor might be another trap

Some .sorry victims reported the criminals' "decryptor" .exe was itself malware. Some were ransomware 2.0 — decrypt old files, encrypt new ones, demand payment again. A twisted double-dip.

Even if you decide to pay, test in an isolated environment first — decrypt a few unimportant files, confirm it works, then go large. Never run an unknown .exe on the infected machine.

Truth 3: Payers get blacklisted

Rarely discussed: companies that pay get marked as "willing payers" and get hit again. Criminals have your contact, know your defences are weak, know you'll pay — you're the perfect repeat customer. One company got hit three times in a year, paid each time. We told them: "You're not paying ransom, you're paying protection money."

The right process: 48 hours is plenty

Criminals say 48 hours, but it's often a bluff. Even if real, 48 hours covers all of this:

  1. First 2 hours: isolate + identify (free)
    Disconnect, photograph the ransom note, confirm .sorry/.mkp via ID Ransomware. We can do preliminary identification free (WhatsApp +852 6558 6806).
  2. First 6 hours: inventory + find backups (free)
    Go folder by folder — what's truly critical? Any cloud versions? Any colleague's clean PC? Any old backups? Often the damage is smaller than feared.
  3. First 24 hours: professional assessment (HK$800–1,500)
    Get us on-site for a full check: shadow copies? Virus version? Recovery feasibility? Don't skimp — this informs your decision.
  4. 24–48 hours: decide
    With full facts, decide: restore from backup, rebuild, or genuinely consider paying (last resort). A decision based on facts, not panic.
Remember: The countdown is psychological warfare. Your 48 hours should be spent doing homework, not panicking. The Sham Shui Po boss used 24 hours for assessment, found 80% of files had cloud versions, and paid nothing.

Real case: Sham Shui Po wholesaler pays zero

The wholesaler's entire shared folder turned .sorry, ransom note demanding 0.3 BTC (~HK$150,000) within 48 hours.

The boss was ready to pay. We stopped him. On-site:

  1. Isolated + identified: confirmed .sorry, no public decryptor.
  2. Inventory: they used Dropbox Business — the entire shared folder was cloud-synced! Opened versions from two days prior on Dropbox — all files there.
  3. One concern: did Dropbox sync the virus too? Checked — Dropbox only syncs files, doesn't execute malware. And we opened them on a clean machine first to verify.
  4. Restored everything from Dropbox in half a day. Then wiped and rescanned all office PCs.

Total: HK$4,200. The boss said: "Nearly sent HK$150,000 to criminals — and that's USD-priced." He's since set Dropbox to 180-day version history and bought an external drive as secondary backup.

When should you genuinely consider paying?

I won't say "never pay" — reality has desperate situations. But ALL of these must hold:

  • ✅ Professional full assessment done, no other path confirmed
  • ✅ Loss value far exceeds ransom (e.g. millions in business vs HK$100k+ ransom)
  • ✅ Handled through a reputable incident response firm — never go on the dark web yourself
  • ✅ Understand the risks: may not recover, may be re-extorted, may be blacklisted
  • ✅ Harden everything immediately after — no second chances

If any one fails, don't pay.

FAQ

1. Q: Criminals say they'll delete keys after 48 hours. True?

A: Sometimes true, often a bluff. Even if true, 48 hours covers full assessment. Don't let the timer lead you.

2. Q: Is .sorry's name a joke?

A: Not a joke — psychological warfare. "Sorry" lowers your hostility, making payment feel like a reasonable transaction. They're not actually sorry.

3. Q: Can Dropbox/Google Drive get infected?

A: The cloud itself doesn't "catch viruses", but if your PC is infected it'll sync encrypted files upward. Cloud version history saves you — just open the old version. That's the cloud's biggest advantage.

4. Q: How do I know if a decryptor works?

A: Test a few unimportant files in an isolated environment (offline clean PC) first. If it works, go large. Never run it directly on the infected machine.

Summary

.sorry/.mkp play psychological games, not technical ones. Countdown timers and "sorry" are designed to make you pay without thinking. Remember: 48 hours isn't for panicking — it's for homework. Isolate, identify, inventory, assess — then decide. Often you'll find you don't need to pay at all.

Got a ransom note and don't know what to do? WhatsApp +852 6558 6806 immediately — free preliminary analysis. Learn prevention in our ransomware protection guide.

Found this article helpful?

Feel free to share it with your friends or colleagues.

Call Us