logo

WantToCry ransomware remotely encrypts files

ID: 1fb77eff-b2fd-5d22-90d6-da65afc33496

STIX ID: report--1fb77eff-b2fd-5d22-90d6-da65afc33496

Feed Name: Sophos Blogs

Threat Score
70/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

...
...

SophosLabs describes the WantToCry ransomware campaign that scans for internet-exposed SMB services, brute-forces weak credentials, exfiltrates files to attacker-controlled infrastructure for remote encryption, then writes encrypted files back to victim hosts and drops ransom notes; the report includes observed IPs and hostnames, detection challenges (no local malware execution), and recommended mitigations (block SMB inbound, disable SMBv1, monitor SMB activity).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.