Exposed SMB: The Hidden Risk Behind ‘WantToCry’ Ransomware Attacks
ID: dfdf027f-4508-53d6-83bb-267c6b36b1ea
STIX ID: report--dfdf027f-4508-53d6-83bb-267c6b36b1ea
Feed Name: Seqrite Blog
**Executive Summary:** The WantToCry ransomware group (active since December 2023) conducts brute‑force attacks against exposed SMB, SSH, FTP, RPC and VNC services to obtain credentials, map and encrypt publicly accessible network shares (appending ".want_to_cry" and dropping "!want_to_cry.txt"), and communicates ransom demands via Telegram and Tox; the report provides IOCs, an execution flow, and mitigation guidance (disable SMB, restrict port 445, enforce authentication, and use behavior‑based detection).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
