Sophos reported that the WantToCry ransomware is targeting internet-exposed SMB services on ports 139 and 445, using weak, brute-forced, or stolen credentials to access shared files without deploying malware on the victim host. Instead of encrypting data locally, the attackers copy files over authenticated SMB sessions to attacker-controlled servers, encrypt them remotely, and write the encrypted versions back to the original shares, appending the .want_to_cry extension and dropping ransom notes such as !want_to_cry.txt or !Want_To_Cry.txt. The notes direct victims to qTox or Telegram and typically demand about $600 in Bitcoin.
Researchers said the technique reduces traditional endpoint detection opportunities because it leaves few host-based artifacts and relies on seemingly normal SMB file operations, though network and authentication traces remain visible. Sophos linked the activity to infrastructure in Russia, Germany, the United States, and Singapore, including systems previously associated with NetSupport RAT and LockBit, Qilin, and ALPHV/BlackCat activity, while noting the ransomware is unrelated to the 2017 WannaCry worm despite the similar name. The company said the attacks appear focused on hosts exposing SMB rather than broad enterprise-wide deployment and urged organizations to block inbound SMB, disable SMBv1 and anonymous access, monitor unusual external SMB activity, and protect backups from SMB-based access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
SC Media summarized Sophos' findings, highlighting that WantToCry abuses exposed SMB services to encrypt files remotely and reduce host-based detection opportunities. The coverage emphasized defensive recommendations including blocking inbound SMB exposure, disabling SMBv1 and anonymous access, and monitoring unusual SMB activity from external IPs.
SophosLabs published research describing the campaign's use of segmented infrastructure and remote encryption, and noted related infrastructure in Russia, Germany, the United States, and Singapore. The company also reported overlaps with systems previously associated with NetSupport RAT and LockBit, Qilin, and ALPHV/BlackCat-related activity, while stating WantToCry is unrelated to the 2017 WannaCry worm.
In observed WantToCry intrusions, attackers authenticated to SMB shares, copied files to attacker-controlled servers for encryption, and wrote the encrypted files back to the original systems. Victims' files were renamed with the .want_to_cry extension and ransom notes such as !Want_To_Cry.txt were dropped, typically demanding about $600 in Bitcoin via qTox or Telegram.
Sophos said the WantToCry ransomware has existed since at least early 2024 and has been used against internet-exposed SMB services on ports 139 and 445. The attacks rely on weak, brute-forced, or stolen credentials rather than local malware execution on victim hosts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcescworld.com
Open sourcesophos.com
Open sourcesophos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.