logo

WantToCry ransomware remotely encrypts files

ID: 29f79d86-583e-54d7-a24d-4a1679905c37

STIX ID: report--29f79d86-583e-54d7-a24d-4a1679905c37

Feed Name: Sophos Blogs

Threat Score
70/100

Date Published: 2026-05-19

Date Updated: 2026-05-27

...
...

SophosLabs analyzed 'WantToCry' ransomware operations where attackers scan for internet-exposed SMB (TCP 139/445), brute-force weak or compromised credentials, exfiltrate files over authenticated SMB sessions to attacker infrastructure for remote encryption, and then write encrypted files back to victims while dropping ransom notes; the report includes observed IP addresses and VM hostnames, describes low ransom demands ($400–$1,800, commonly $600), notes detection challenges because there is no local malware execution, and recommends disabling/locking down SMB, blocking inbound SMB, and using file-content monitoring and XDR.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.