logo

Exposed SMB: The Hidden Risk Behind ‘WantToCry’ Ransomware Attacks

ID: dfdf027f-4508-53d6-83bb-267c6b36b1ea

STIX ID: report--dfdf027f-4508-53d6-83bb-267c6b36b1ea

Feed Name: Seqrite Blog

Threat Score
75/100

Date Published: 2025-01-31

Date Updated: 2026-04-30

Author: Umar Khan A

...
...

**Executive Summary:** The WantToCry ransomware group (active since December 2023) conducts brute‑force attacks against exposed SMB, SSH, FTP, RPC and VNC services to obtain credentials, map and encrypt publicly accessible network shares (appending ".want_to_cry" and dropping "!want_to_cry.txt"), and communicates ransom demands via Telegram and Tox; the report provides IOCs, an execution flow, and mitigation guidance (disable SMB, restrict port 445, enforce authentication, and use behavior‑based detection).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.