WantToCry Ransomware Exploits SMB Services To Encrypt Files Remotely
ID: b2bf4b3e-724a-5962-b963-3bed71d7f043
STIX ID: report--b2bf4b3e-724a-5962-b963-3bed71d7f043
Feed Name: Cyber Press
The report details a ransomware campaign called WantToCry that gains access via brute-forced or compromised SMB credentials on TCP ports 139/445, pulls files to attacker infrastructure, performs encryption remotely, and overwrites originals; victims receive a ransom note (!Want_To_Cry.txt) and files are appended with .want_to_cry. The actors demand modest ransoms ($400–$1,800), communicate via QTox or Telegram, and notably leave no local malware footprint—making EDRs that rely on local process detection ineffective—so defenders are advised to harden SMB exposure, block ports 139/445, disable SMBv1, and monitor for rapid file-content changes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
