.sorry / .mkp Ransomware Decryption: Don't Rush to Pay the Ransom

.sorry / .mkp Ransomware Decryption: Don't Rush to Pay the Ransom
One Friday afternoon in August, a wholesaler in Sham Shui Po called us, voice urgent: "All our files turned .sorry. The ransom note says if we don't pay 0.3 BTC within 48 hours they'll delete the decryption keys. Should we just pay?" I stopped him immediately: "Hold on! Don't touch your wallet yet — hear me out first."
Typical reaction. .sorry and .mkp excel at using "deadlines" to pressure you. The name .sorry is cheeky enough — criminals saying sorry while asking for money. Here's why you shouldn't rush.
The .sorry / .mkp psychological game
These variants aren't the most technically advanced (standard AES-256), but their "marketing" is slick:
- Countdown timers: Ransom notes include a timer (some dynamic HTML, some just "48 hours"), creating urgency. Psychologically, people make poor decisions under time pressure — criminals know this.
- The "sorry" hypocrisy: .sorry notes often open with "Sorry about that!" or "We are sorry to inform you..." — as if they didn't want to do it, lowering your hostility so "paying to solve it" feels reasonable.
- .mkp loves shared folders: .mkp particularly targets network shared folders. SMEs often run whole departments on one shared folder — one hit stops everyone, maximising pressure.
- Tiered pricing: "0.3 BTC within 48 hours, 0.6 after" — making you feel "pay early, save money". Really it's rushing you past clear thinking.
The Sham Shui Po boss nearly fell for it. "I thought, short pain beats long pain — just pay and be done." Luckily he called us first.
Why not rush? Three harsh truths
Truth 1: Payment doesn't guarantee recovery
Tracking .sorry/.mkp cases where ransoms were paid:
- ~60%: Got a decryptor, recovered most files (but not all — some corrupt)
- ~20%: Got a decryptor that didn't work / corrupted everything
- ~20%: Paid, criminals vanished
So your HK$150,000 has a 40% chance of going down the drain. Still feel like "short pain"?
Truth 2: The decryptor might be another trap
Some .sorry victims reported the criminals' "decryptor" .exe was itself malware. Some were ransomware 2.0 — decrypt old files, encrypt new ones, demand payment again. A twisted double-dip.
Even if you decide to pay, test in an isolated environment first — decrypt a few unimportant files, confirm it works, then go large. Never run an unknown .exe on the infected machine.
Truth 3: Payers get blacklisted
Rarely discussed: companies that pay get marked as "willing payers" and get hit again. Criminals have your contact, know your defences are weak, know you'll pay — you're the perfect repeat customer. One company got hit three times in a year, paid each time. We told them: "You're not paying ransom, you're paying protection money."
The right process: 48 hours is plenty
Criminals say 48 hours, but it's often a bluff. Even if real, 48 hours covers all of this:
- First 2 hours: isolate + identify (free)
Disconnect, photograph the ransom note, confirm .sorry/.mkp via ID Ransomware. We can do preliminary identification free (WhatsApp +852 6558 6806). - First 6 hours: inventory + find backups (free)
Go folder by folder — what's truly critical? Any cloud versions? Any colleague's clean PC? Any old backups? Often the damage is smaller than feared. - First 24 hours: professional assessment (HK$800–1,500)
Get us on-site for a full check: shadow copies? Virus version? Recovery feasibility? Don't skimp — this informs your decision. - 24–48 hours: decide
With full facts, decide: restore from backup, rebuild, or genuinely consider paying (last resort). A decision based on facts, not panic.
Real case: Sham Shui Po wholesaler pays zero
The wholesaler's entire shared folder turned .sorry, ransom note demanding 0.3 BTC (~HK$150,000) within 48 hours.
The boss was ready to pay. We stopped him. On-site:
- Isolated + identified: confirmed .sorry, no public decryptor.
- Inventory: they used Dropbox Business — the entire shared folder was cloud-synced! Opened versions from two days prior on Dropbox — all files there.
- One concern: did Dropbox sync the virus too? Checked — Dropbox only syncs files, doesn't execute malware. And we opened them on a clean machine first to verify.
- Restored everything from Dropbox in half a day. Then wiped and rescanned all office PCs.
Total: HK$4,200. The boss said: "Nearly sent HK$150,000 to criminals — and that's USD-priced." He's since set Dropbox to 180-day version history and bought an external drive as secondary backup.
When should you genuinely consider paying?
I won't say "never pay" — reality has desperate situations. But ALL of these must hold:
- ✅ Professional full assessment done, no other path confirmed
- ✅ Loss value far exceeds ransom (e.g. millions in business vs HK$100k+ ransom)
- ✅ Handled through a reputable incident response firm — never go on the dark web yourself
- ✅ Understand the risks: may not recover, may be re-extorted, may be blacklisted
- ✅ Harden everything immediately after — no second chances
If any one fails, don't pay.
FAQ
1. Q: Criminals say they'll delete keys after 48 hours. True?
A: Sometimes true, often a bluff. Even if true, 48 hours covers full assessment. Don't let the timer lead you.
2. Q: Is .sorry's name a joke?
A: Not a joke — psychological warfare. "Sorry" lowers your hostility, making payment feel like a reasonable transaction. They're not actually sorry.
3. Q: Can Dropbox/Google Drive get infected?
A: The cloud itself doesn't "catch viruses", but if your PC is infected it'll sync encrypted files upward. Cloud version history saves you — just open the old version. That's the cloud's biggest advantage.
4. Q: How do I know if a decryptor works?
A: Test a few unimportant files in an isolated environment (offline clean PC) first. If it works, go large. Never run it directly on the infected machine.
Summary
.sorry/.mkp play psychological games, not technical ones. Countdown timers and "sorry" are designed to make you pay without thinking. Remember: 48 hours isn't for panicking — it's for homework. Isolate, identify, inventory, assess — then decide. Often you'll find you don't need to pay at all.
Got a ransom note and don't know what to do? WhatsApp +852 6558 6806 immediately — free preliminary analysis. Learn prevention in our ransomware protection guide.
Found this article helpful?
Feel free to share it with your friends or colleagues.