WantToCry is a ransomware operation that targets internet-exposed SMB services by authenticating with weak or compromised credentials rather than relying on software exploitation. The operation is notable for performing encryption remotely: operators scan for exposed SMB, brute-force or otherwise obtain valid SMB credentials, exfiltrate files over authenticated SMB sessions to attacker-controlled infrastructure, encrypt the files off-host, and then write the encrypted data back to the victim system. This tradecraft reduces conventional endpoint detection opportunities because it does not require local ransomware execution, suspicious process creation, or a substantial on-host payload. Observed attacks appear focused primarily on hosts directly exposing SMB to the internet rather than broad enterprise-wide deployment, and there is no high-confidence evidence that the operation is self-propagating or related to the 2017 WannaCry worm beyond name similarity. Reported ransom demands have generally been comparatively low, and there is no high-confidence evidence that WantToCry has used stolen data for double extortion or leak-site pressure. The operation has been associated with abuse of virtual-machine infrastructure provisioned through ISPsystem to support attack activity at scale. Reporting on industrial ransomware activity highlighted this technique as particularly concerning for legacy file-sharing environments, including engineering and OT-adjacent networks where exposed SMB may still be present. Known aliases include wanttocry and wanttocry_operators.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an operation demonstrating remote encryption of exposed SMB services without a local payload.
Conducting ransomware attacks by scanning for internet-exposed SMB services, brute-forcing weak or compromised credentials, exfiltrating files over authenticated SMB sessions to attacker-controlled infrastructure for remote encryption, then writing encrypted files back and leaving ransom notes.
Abuses ISPsystem-provisioned virtual machines (likely via intermediaries/bulletproof hosting) to host and deliver malicious payloads at scale.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.