WantToCry Ransomware Exploits SMB to Encrypt Remote Files
ID: 05eae5ad-22ad-5761-8468-b01bda822b88
STIX ID: report--05eae5ad-22ad-5761-8468-b01bda822b88
Feed Name: GBHackers
Sophos observed a ransomware campaign called "WantToCry" that targets internet-facing SMB (TCP 139/445) by scanning for exposed systems, conducting brute-force authentication, exfiltrating files over SMB to attacker infrastructure for remote encryption, and writing back encrypted files with a ".want_to_cry" extension and ransom notes. The operation avoids deploying executables on victims, reducing EDR detectability; demands typically range $400–$1,800; researchers observed related infrastructure across multiple countries and recurring VM hostnames, and emphasize mitigating actions such as disabling SMBv1, blocking inbound SMB, enforcing strong authentication, and monitoring unusual SMB activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
