logo

WantToCry Ransomware Leverages Exposed SMB for Remote Encryption Loops

ID: 6ada3d3a-e0e2-57f0-bd2a-efdbd65bd7d1

STIX ID: report--6ada3d3a-e0e2-57f0-bd2a-efdbd65bd7d1

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-05-23

Date Updated: 2026-05-23

Author: Ddos

...
...

Sophos CTU describes "WantToCry", a ransomware campaign that discovers internet‑exposed SMB servers, brute‑forces credentials, and performs remote file reads, encrypts files on attacker infrastructure, then writes encrypted files back to victims—achieving destruction without executing local malware. The report includes tracked IPs and hostnames, ransom note behavior (qTox/Telegram and Bitcoin/USDT addresses), and highlights the challenge this technique poses to traditional EDRs because no malicious binaries or local processes are observable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.