WantToCry is a ransomware operation that targets internet-exposed Windows Server Message Block (SMB) file-sharing services and performs remote encryption without executing a local ransomware payload on the victim host. Operators scan for exposed SMB services, use brute-force or otherwise compromised credentials to authenticate, copy victim files over SMB to attacker-controlled infrastructure, encrypt the data remotely, and then write the encrypted files back to their original locations. This tradecraft minimizes host-based artifacts such as malicious processes, dropped binaries, or registry changes, reducing the effectiveness of traditional endpoint-focused detection and response controls.
Observed attacks primarily affect systems directly exposing SMB to the internet rather than relying on worm-like propagation or broad post-compromise movement. WantToCry is not self-propagating and there is no evidence linking it to the 2017 WannaCry worm beyond the name similarity. Encrypted files are renamed with a characteristic extension and ransom notes are left for victim contact and payment negotiation. Reported ransom demands have generally been relatively low compared with many enterprise ransomware operations, and victims have been offered limited test decryption. There is no confirmed evidence that the operation routinely uses stolen data for double extortion or public leak-site pressure.
Investigations linked WantToCry activity to attacker infrastructure hosted on leased virtual machines, including systems provisioned through ISPsystem VMmanager-derived Windows templates. Similar template-derived hostnames have also appeared in unrelated criminal operations, so shared naming alone does not establish common actor attribution. The operation is notable for abusing legitimate SMB functionality and authenticated file access rather than exploiting a software vulnerability, making exposed file-sharing infrastructure, weak credential hygiene, and inadequate network exposure controls the primary risk factors. Organizations with legacy file-sharing deployments, including engineering and OT-adjacent environments that still expose or depend on SMB, are particularly susceptible.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Because no untrusted binaries are executed, no malicious registry edits are created, and no unexpected system processes run locally on the target server, local anti-malware tools remain entirely blind to the destruction occurring across the network file shares.
WantToCry operators identify potential victims by scanning the internet for open SMB ports. The threat actors likely use the same reconnaissance services as legitimate security teams. Services such as Shodan and Censys continuously scan internet-facing systems, creating readily available databases of exposed services that attackers can leverage for target selection.
According to the Shodan search engine, the two hostnames were associated with thousands of internet-facing devices exposing RDP services (TCP port 3389) in December 2025.
The remote servers systematically issue file-read requests to pull documents over the network, encrypt them locally on the attacker’s own hardware...
After successfully authenticating using compromised or weak credentials, the attackers initiated file exfiltration via authenticated SMB sessions. The subsequent encryption process was initiated on the exfiltrated files stored on attacker-controlled infrastructure.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware operation notable for remotely encrypting exposed SMB services without deploying a local payload, increasing risk to legacy file-sharing infrastructure in engineering and OT-adjacent environments.
Ransomware that encrypts victim files remotely over authenticated SMB sessions without executing malware locally on the target. The operators scan for internet-exposed SMB services, brute-force weak credentials, read files over the network, encrypt them on attacker-controlled systems, and write the encrypted files back, reducing local detection opportunities.
Ransomware that abuses exposed SMB services for initial access, uses brute-force or compromised credentials, exfiltrates files to attacker-controlled infrastructure for remote encryption, then writes encrypted files back to the victim system. It appends the .want_to_cry extension and drops a !Want_To_Cry.txt ransom note.
Ransomware that targets exposed SMB services, gains authenticated SMB access via brute force or compromised credentials, exfiltrates files for remote encryption on attacker-controlled servers, and writes encrypted files back to victim systems to reduce endpoint detection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.