WantToCry Ransomware Leverages Exposed SMB for Remote Encryption Loops
ID: 6ada3d3a-e0e2-57f0-bd2a-efdbd65bd7d1
STIX ID: report--6ada3d3a-e0e2-57f0-bd2a-efdbd65bd7d1
Feed Name: securityonline.info
Sophos CTU describes "WantToCry", a ransomware campaign that discovers internet‑exposed SMB servers, brute‑forces credentials, and performs remote file reads, encrypts files on attacker infrastructure, then writes encrypted files back to victims—achieving destruction without executing local malware. The report includes tracked IPs and hostnames, ransom note behavior (qTox/Telegram and Bitcoin/USDT addresses), and highlights the challenge this technique poses to traditional EDRs because no malicious binaries or local processes are observable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
