Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
ClickFix Users Exposed to Malware via Polygon Blockchain Infrastructure
August 11, 2026
Critical FortiGate RCE CVE-2022-42475 Exploited in Polish Energy Sector Attack
August 11, 2026
GhostJacking Attack Hijacks AI Agents to Run Malicious Code on Developer Machines
August 11, 2026
Home/CyberSecurity News/WantToCry Ransomware Exploits SMB Vulnerability to Remotely Encrypt Files
CyberSecurity News

WantToCry Ransomware Exploits SMB Vulnerability to Remotely Encrypt Files

Key Takeaways WantToCry ransomware is actively targeting organizations by exploiting exposed Server Message Block (SMB) services. Unlike its namesake, WannaCry, WantToCry does not self-propagate but...

Sarah simpson
Sarah simpson
May 21, 2026 5 Min Read
60 0

Key Takeaways

  • WantToCry ransomware is actively targeting organizations by exploiting exposed Server Message Block (SMB) services.
  • Unlike its namesake, WannaCry, WantToCry does not self-propagate but relies on initial access via brute-forcing weak or compromised SMB credentials.
  • The encryption process occurs remotely on attacker-controlled infrastructure, making traditional endpoint detection methods less effective.
  • Over 1.5 million devices globally had SMB ports (TCP 139 and 445) exposed to the internet as of January 7, 2026, creating a vast attack surface.

WantToCry Ransomware Exploits Exposed SMB Services

A new ransomware variant, dubbed WantToCry, is actively compromising businesses by leveraging vulnerabilities in the Server Message Block (SMB) protocol. This sophisticated threat remotely encrypts files on target systems, marking a significant evolution in ransomware tactics, as detailed in a recent analysis. The attacks highlight a critical risk for any organization maintaining internet-exposed file-sharing services.

Table Of Content

  • Key Takeaways
  • WantToCry Ransomware Exploits Exposed SMB Services
  • Stealthy Remote Encryption
  • How WantToCry Abuses SMB Services to Encrypt Files
  • Detection Challenges and Defensive Steps
  • What You Should Do

While sharing a name with the infamous 2017 WannaCry global ransomware worm, WantToCry operates with a distinct methodology. Crucially, it does not possess worm-like self-propagation capabilities, and there is no evidence to suggest any direct operational link between the two. Their commonality lies in their target: organizations that have inadvertently left SMB ports accessible from the public internet.

Stealthy Remote Encryption

SophosLabs researchers conducted an in-depth investigation into WantToCry incidents. Their findings reveal that threat actors gain initial access by abusing exposed SMB services, subsequently exfiltrating victim files to their own remote infrastructure for encryption. This “off-site” encryption method significantly reduces the ransomware’s detection footprint. “The detection surface is significantly reduced because WantToCry operates without local malware execution, with no post-compromise activity beyond exfiltrating files and rewriting them to disk,” Sophos stated in a report shared with Cyber Security News (CSN).

The campaign’s impact is noteworthy not for the relatively modest ransom demands, which have been observed ranging from $400 to $1,800 per victim, but for its operational stealth. No malicious software is installed or executed on the victim’s machine. The entire encryption process occurs externally, on infrastructure controlled by the attackers, making it exceptionally challenging for conventional security tools to identify and block.

This widespread exposure poses a substantial risk. As of January 7, 2026, more than 1.5 million devices globally had SMB ports TCP 139 and 445 directly exposed to the internet. Each of these could become a target if their credentials are weak or already compromised.

How WantToCry Abuses SMB Services to Encrypt Files

WantToCry operators initiate their attacks by actively scanning the internet for systems with open SMB ports. They leverage publicly available reconnaissance tools such as Shodan and Censys—platforms also utilized by legitimate security teams—to compile lists of potential targets. Upon identifying a vulnerable system, they launch automated brute-force attacks against the exposed SMB service, attempting to gain unauthorized access using weak or previously leaked credentials.

Once authenticated, the attackers do not deploy any malware to the compromised machine. Instead, they establish an authenticated SMB session to pull the victim’s files to their external infrastructure. The files are encrypted remotely, and then the encrypted versions are pushed back to their original locations on the victim’s system. Affected files are then renamed with a .want_to_cry extension, and a ransom note, typically named !Want_To_Cry.txt, is placed in the directories, demanding Bitcoin payment.

Analysts observed two distinct ransom note templates during the campaign. One note instructed victims to contact the attackers via qTox, while a nearly identical version provided a Telegram account for communication. Victims were offered the opportunity to decrypt up to three files as proof of capability before submitting to the ransom, with demands in observed incidents averaging $600 per victim.

Detection Challenges and Defensive Steps

The unique operational model of WantToCry presents significant detection challenges. Since no malicious code executes locally, endpoint detection and response (EDR) tools relying on suspicious process activity or known malware signatures are largely ineffective. Security solutions typically interpret SMB file operations as legitimate system behavior, allowing the attack to blend seamlessly into normal network traffic. Therefore, security tools capable of monitoring file content changes and detecting encryption irrespective of its source offer a more robust defense.

Augmenting defenses with network monitoring provides another crucial layer of protection. WantToCry operations, despite their stealth, leave observable artifacts, notably sustained SMB read and write activity originating from external IP addresses, often occurring at unusual volumes or outside regular business hours. Furthermore, repeated brute-force attempts against SMB services can serve as an early warning indicator before actual encryption commences.

What You Should Do

  • Disable SMBv1: Immediately disable the outdated and insecure SMBv1 protocol across all systems.
  • Block External SMB Access: Configure internet-facing firewalls to block all inbound SMB traffic on ports TCP 139 and TCP 445. SMB services should never be directly exposed to the internet.
  • Strengthen Credentials: Enforce strong, unique passwords for all accounts, especially those with SMB access, and implement multi-factor authentication (MFA) where possible.
  • Remove Guest Access: Eliminate guest or anonymous access to SMB shares.
  • Isolate Backups: Ensure that backup systems and their data are logically and physically isolated from network access via SMB protocols to prevent their encryption.
  • Implement Advanced Detection: Deploy Extended Detection and Response (XDR) tools capable of identifying reconnaissance and brute-force activity against SMB services, as well as file integrity monitoring solutions that detect unauthorized encryption.
  • Monitor Network Traffic: Actively monitor network traffic for unusual SMB activity, particularly sustained read/write operations from external IPs or during off-hours.

Indicators of Compromise (IoCs):-

Type Indicator Description
IP Address 87.225.105.217 Russia-based hosting provider IP used for reconnaissance and brute-force SMB authentication attempts
IP Address 109.69.58.213 Attacker-controlled encryption infrastructure, geolocated to Germany
IP Address 185.189.13.56 Attacker-controlled encryption infrastructure, geolocated to Russian Federation
IP Address 185.200.191.37 Attacker-controlled encryption infrastructure, geolocated to United States of America
IP Address 194.36.179.18 Attacker-controlled encryption infrastructure, geolocated to Singapore
IP Address 194.36.179.30 Attacker-controlled encryption infrastructure, geolocated to Singapore
File Name !Want_To_Cry.txt Ransom note dropped into affected directories on victim systems
File Extension .want_to_cry Extension appended to all files encrypted by WantToCry ransomware
URL hxxps://t[.]me/want_to_cry_team Telegram contact channel listed in one variant of the WantToCry ransom note
Host Name WIN-J9D866ESJ2 Windows Server 2016 virtual machine used in WantToCry attack infrastructure
Host Name WIN-LVFRVQFMKO Windows Server 2019 virtual machine observed in WantToCry attack infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwareransomwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Two US Executives Plead Guilty in India-Based Tech Support Fraud

Next Post

Critical NGINX Vulnerability CVE-2024-35200 Lets Attackers Achieve RCE

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical LiteLLM Supply Chain Flaw Exposes 2,500 Companies, 434,000 CI/CD Pipelines
August 11, 2026
CISA Warns of Critical SonicWall SMA 1000 Zero-Days Exploited in Ransomware Attacks
August 11, 2026
Critical VMware vCenter CVE-2023-34048 Under Active Exploitation
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us