logo

WantToCry Ransomware Exploits SMB to Encrypt Remote Files

ID: 05eae5ad-22ad-5761-8468-b01bda822b88

STIX ID: report--05eae5ad-22ad-5761-8468-b01bda822b88

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Mayura Kathir

...
...

Sophos observed a ransomware campaign called "WantToCry" that targets internet-facing SMB (TCP 139/445) by scanning for exposed systems, conducting brute-force authentication, exfiltrating files over SMB to attacker infrastructure for remote encryption, and writing back encrypted files with a ".want_to_cry" extension and ransom notes. The operation avoids deploying executables on victims, reducing EDR detectability; demands typically range $400–$1,800; researchers observed related infrastructure across multiple countries and recurring VM hostnames, and emphasize mitigating actions such as disabling SMBv1, blocking inbound SMB, enforcing strong authentication, and monitoring unusual SMB activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.