Threat reportRansomwareTL-2026-0531
WantToCry Ransomware — Remote SMB Encryption Campaign Targeting Internet-Exposed TCP 139/445 (Sophos CTU)
WantToCry Ransomware (TL-2026-0531), also tracked as Want_To_Cry, is a high-severity ransomware operation, first published 2026-05-19. It is attributed to WantToCry operators with low confidence, affects Microsoft Windows Server (SMB service), maps to 27 MITRE ATT&CK techniques (T1020, T1021, T1021.002), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 27MITRE ATT&CK
- Actors
- 1WantToCry operators
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-0531
- Threat ID
- TL-2026-0531
- Also known as
- Want_To_Cry, WantToCry
- Severity
- HIGH
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- Last reviewed
- Attribution
- WantToCry operators
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- small-medium-business, managed-service-providers, hosting-providers, healthcare, education, manufacturing, professional-services, consumer-prosumer
- Target regions
- North America, Europe, Asia-Pacific, Latin America
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in WantToCry Ransomware
Malware and tooling: HEUR:Trojan.Win32.EncrSD, WantToCry
How WantToCry Ransomware works
Sophos Counter Threat Unit disclosed a WantToCry ransomware campaign in which operators brute-force internet-exposed SMB services on TCP 139/445, then read victim files over an authenticated SMB session, encrypt them on attacker-controlled infrastructure, and write the encrypted blobs back to the original share — producing a ransomware impact with no malware ever executing on the victim host. Encrypted files receive the .want_to_cry extension and a !Want_To_Cry.txt ransom note is dropped to affected shares, with ransom demands of $400-$1,800 (typically $600) negotiated over qTox or Telegram (@want_to_cry_team). Shodan identifies roughly 1.5 million devices exposing SMB to the internet, with the United States the most-exposed country.
WantToCry is a financially motivated ransomware operation that has been active since at least December 2023, but Sophos Counter Threat Unit (CTU) published a deep technical analysis on 2026-05-19 detailing a novel remote-encryption tradecraft that the operators have refined in 2025-2026. Unlike conventional ransomware that requires a binary to execute on the victim endpoint, WantToCry weaponises the SMB (Server Message Block) protocol itself: the attacker brute-forces credentials against internet-exposed SMB services on TCP 139 and 445, authenticates as a legitimate user, opens a session to writable shares (commonly NAS appliances, file servers, and small-business storage), reads the victim files over SMB to attacker infrastructure, encrypts them there, and writes the encrypted result back to the original share via the same SMB session. The technique is architecturally similar to a man-in-the-middle file rewrite and intentionally eliminates the local malware footprint that EDR and CryptoGuard-style behavioural engines rely on.
The brute-force stage is automated and high-volume. Multiple vendors (Sophos, Seqrite, Quick Heal) report that the actors maintain a curated database of over one million credentials spanning common defaults, leaked password lists, and previously breached accounts, and target not only SMB but also SSH, FTP, RPC, and VNC where they are exposed. Once authenticated, the operators enumerate shares, identify file types of interest, and run their remote-encryption tooling. Sophos telemetry traced the operations to a series of ISPsystem-managed virtual machines repurposed through bulletproof hosting, with computer names WIN-J9D866ESIJ2 (Windows Server 2016) and WIN-LIVFRVQFMKO (Windows Server 2019) — VM names that have also appeared in unrelated NetSupport RAT, LockBit, Qilin, and BlackCat operations, suggesting a shared bulletproof-hosting estate rather than direct actor overlap.
Victim files are renamed with a .want_to_cry suffix (e.g. quarterly_report.xlsx → quarterly_report.xlsx.want_to_cry) and a ransom note titled !Want_To_Cry.txt is dropped at the root of each affected share. Two ransom note variants have been observed: an earlier variant directed victims to a qTox ID (963E6F7F58A67DEACBC2845469850B9A00E20E4000CE71B35DE789ABD0BE2F70D4147D5C0C91), and a later variant directing victims to https://t.me/want_to_cry_team on Telegram. Operators offer to decrypt up to three sample files as a proof of capability. Observed ransom demands range from US$400 to US$1,800, clustered around US$600 — a low-value, high-volume model consistent with the opportunistic brute-force targeting pattern.
The campaign is not self-propagating and contains no exploit-based initial access. Despite the name, WantToCry has no technical relationship to WannaCry/WCry (2017): there is no MS17-010 / EternalBlue worm component, no kernel-level shellcode, and no kill-switch domain. The name appears to be a deliberate homage chosen for psychological effect on victims. Equally, no double-extortion or data leak site has been associated with WantToCry — the operators monetise exclusively through decryption sales.
The defensive impact is significant because the entire encryption operation can occur with the victim host showing nothing more than a series of SMB READ and WRITE operations from an authenticated session. Traditional anti-ransomware controls (CryptoGuard, Controlled Folder Access, on-host behaviour rules) cannot trigger because no process on the victim is performing the encryption. Detection must shift to (a) SMB session-level analytics (unusual file-rename patterns, mass write-with-extension-change), (b) authentication telemetry (geo-anomalous SMB logons, brute-force lockouts), and (c) external attack surface management to remove TCP 139/445 from the internet entirely. As of 2026-01-07, Sophos cites Shodan data showing ~1.5 million devices exposing SMB to the public internet, with the United States, China, Hong Kong, and Russia accounting for the majority. Small and mid-size organisations, ISPs, and NAS-heavy environments (Synology, QNAP, TrueNAS) face the highest risk.
MITRE ATT&CK techniques used in TL-2026-0531
Exfiltration
T1020 Automated Exfiltration; T1048 Exfiltration Over Alternative Protocol
Lateral Movement
T1021 Remote Services; T1021.002 Remote Services: SMB/Windows Admin Shares
Collection
T1039 Data from Network Shared Drive
Discovery
T1046 Network Service Discovery; T1083 File and Directory Discovery; T1135 Network Share Discovery
Defense Evasion
T1070.004 Indicator Removal: File Deletion; T1564 Hide Artifacts
Command and Control
T1071 Application Layer Protocol; T1573.002 Encrypted Channel: Asymmetric Cryptography
Initial Access
T1078 Valid Accounts; T1078.003 Valid Accounts: Local Accounts; T1133 External Remote Services
Credential Access
T1110 Brute Force; T1110.004 Brute Force: Credential Stuffing
credential-access
T1110.001 Brute Force: Password Guessing
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1565.001 Data Manipulation: Stored Data Manipulation
Resource Development
T1583.003 Acquire Infrastructure: Virtual Private Server; T1583.004 Acquire Infrastructure: Server
Reconnaissance
T1592 Gather Victim Host Information; T1595 Active Scanning; T1595.001 Active Scanning: Scanning IP Blocks; T1595.002 Active Scanning: Vulnerability Scanning
Affected products and versions in WantToCry Ransomware
- Microsoft — Windows Server (SMB service)
Vulnerable versions: any version with internet-exposed TCP 139/445 and weak credentials
Fixed in: N/A — configuration hardening required - Synology — DiskStation Manager (SMB / File Station)
Vulnerable versions: any DSM with internet-exposed SMB and weak account passwords
Fixed in: N/A — disable internet exposure - QNAP — QTS / QuTS hero (SMB / Microsoft Networking)
Vulnerable versions: any QTS with internet-exposed SMB and weak account passwords
Fixed in: N/A — disable internet exposure - iXsystems — TrueNAS (SMB share)
Vulnerable versions: any TrueNAS with internet-exposed SMB
Fixed in: N/A — disable internet exposure - Samba Team — Samba (smbd)
Vulnerable versions: any Samba deployment exposed to the internet with weak credentials
Fixed in: N/A — configuration hardening required
Remediation for WantToCry Ransomware
Patches
- There is no CVE associated with WantToCry — the campaign exploits weak credentials and exposure, not a software vulnerability. No patch is applicable; configuration hardening is the remediation.
Immediate actions
- Block inbound TCP 139 and TCP 445 at the perimeter firewall — there is no legitimate reason to expose SMB to the internet
- Audit external attack surface (Shodan, Censys, internal ASM) for any host with SMB reachable from the internet and remove it immediately
- Force a password reset on all SMB-authenticated accounts, especially service and guest accounts, and disable any account using default credentials
- Disable SMB guest access and anonymous SMB access organisation-wide (Windows: 'Enable insecure guest logons' = Disabled; Samba: 'guest ok = no', 'map to guest = never')
- Block the published WantToCry IOC IPs (87.225.105.217, 109.69.58.213, 185.189.13.56, 185.200.191.37, 194.36.179.18, 194.36.179.30, 194.36.178.133) at perimeter, DNS sinkhole, and SIEM watchlist
Workarounds
- If SMB must remain reachable for remote workers, restrict source IPs via firewall ACL to known corporate ranges only and require VPN authentication first
- On NAS appliances (Synology, QNAP, TrueNAS) disable internet exposure, disable default admin accounts, and enable 2FA on all admin logins
- Enable Windows Defender Attack Surface Reduction rule 'Block credential stealing from the Windows local security authority subsystem' and 'Block process creations originating from PSExec and WMI commands' to limit follow-on activity if credentials are stolen
Longer-term hardening
- Deploy SMB session-level monitoring (zeek smb-files, Microsoft SMB auditing, Darktrace, Vectra) to detect mass file-rename and extension-change patterns regardless of source
- Enforce SMB signing and require SMBv3 with encryption; disable SMBv1 entirely on all hosts and NAS appliances
- Place NAS and file-server shares behind VPN or zero-trust network access (ZTNA); never expose them directly
- Implement immutable / air-gapped / object-lock backups so that any future SMB-write-back attack cannot encrypt the backup tier
- Enable account lockout and rate-limiting on SMB authentication; alert on credential-stuffing patterns against TCP 139/445
- Move to certificate or Kerberos-only authentication for file shares where possible; eliminate NTLM and local-account SMB authentication
Weaknesses (CWE) in WantToCry Ransomware
Timeline of WantToCry Ransomware
- WantToCry operators first observed conducting opportunistic SMB brute-force activity against internet-exposed hosts; group emerges on underground forums offering low-value decryption services
- First confirmed WantToCry encryption events observed in the wild — ransom note !Want_To_Cry.txt and .want_to_cry file extension catalogued by multiple AV vendors
- Seqrite, Quick Heal, and NPAV publish initial blog posts describing the SMB brute-force methodology, the >1M-credential password database, and Telegram contact channel
- Elastio adds deep-file-inspection signatures for WantToCry-encrypted blobs in backup data
- Cybersecurity News reports a renewed wave of WantToCry attacks specifically targeting NAS devices (Synology, QNAP) with exposed SMB
- Darktrace publishes research on robust identification of ransomware encryption over SMB, citing WantToCry-style remote encryption as the motivating use case
- Sophos Counter Threat Unit begins formal investigation into the WantToCry remote-encryption tradecraft after multiple customer incidents
- Sophos CTU samples Shodan: ~1.5 million devices globally expose TCP 139/445 to the internet; United States leads exposure
- Threadlinqs Intelligence publishes TL-2026-0531 with full MITRE mapping, IOCs, simulations, and SIEM detections for SOC operationalisation
- Sophos CTU publishes detailed technical analysis on the WantToCry remote-encryption-over-SMB tradecraft, releasing IOC IPs, attacker VM names, and detection guidance
- As of 2026-05-29, WantToCry remains an active, financially-motivated SMB brute-force remote-encryption campaign, freshly detailed by Sophos CTU on 2026-05-19 and widely re-reported (SC Media, TechRadar, GBHackers). No CVE, takedown, or operator arrest exists; ~1.5M internet-exposed SMB hosts and operators still reachable via qTox/Telegram keep it live.
Sources cited for WantToCry Ransomware
- WantToCry ransomware remotely encrypts files (Sophos Counter Threat Unit)
- WantToCry Ransomware Exploits SMB Vulnerabilities to Remotely Encrypt NAS Drives
- Exposed SMB: The Hidden Risk Behind WantToCry Ransomware Attacks
- Exposed SMB: The Hidden Risk Behind WantToCry Ransomware Attacks (Quick Heal)
- What is WantToCry Ransomware? (Elastio)
- Robust identification of ransomware encryption over SMB (Darktrace)
- WantToCry Ransomware Exploits SMB Vulnerabilities: A Serious Cybersecurity Threat (NPAV)
Detection coverage for TL-2026-0531
As of 2026-05-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0531 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.