WantToCry ransomware remotely encrypts files
ID: 1fb77eff-b2fd-5d22-90d6-da65afc33496
STIX ID: report--1fb77eff-b2fd-5d22-90d6-da65afc33496
Feed Name: Sophos Blogs
Threat Score
SophosLabs describes the WantToCry ransomware campaign that scans for internet-exposed SMB services, brute-forces weak credentials, exfiltrates files to attacker-controlled infrastructure for remote encryption, then writes encrypted files back to victim hosts and drops ransom notes; the report includes observed IPs and hostnames, detection challenges (no local malware execution), and recommended mitigations (block SMB inbound, disable SMBv1, monitor SMB activity).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
