logo

WantToCry Ransomware Exploits SMB Services To Encrypt Files Remotely

ID: b2bf4b3e-724a-5962-b963-3bed71d7f043

STIX ID: report--b2bf4b3e-724a-5962-b963-3bed71d7f043

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Varshini

...
...

The report details a ransomware campaign called WantToCry that gains access via brute-forced or compromised SMB credentials on TCP ports 139/445, pulls files to attacker infrastructure, performs encryption remotely, and overwrites originals; victims receive a ransom note (!Want_To_Cry.txt) and files are appended with .want_to_cry. The actors demand modest ransoms ($400–$1,800), communicate via QTox or Telegram, and notably leave no local malware footprint—making EDRs that rely on local process detection ineffective—so defenders are advised to harden SMB exposure, block ports 139/445, disable SMBv1, and monitor for rapid file-content changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.