‘Detection surface is significantly reduced’: Sophos report warns new ‘WantToCry’ ransomware could pose significant risk to your business, here’s what we know



  • Sophos identified a new ransomware variant called WantToCry that remotely encrypts files after the breach, reducing opportunities for detection.
  • Attackers exploit exposed SMB services with weak credentials and then overwrite victims’ files with encrypted versions.
  • Ransom demands are unusually low, between $600 and $1,800, reflecting limited reach and lack of broad network impact.

Security researchers at Sophos observed a new ransomware variant called WantToCry that, thanks to its encryption mechanism, is much harder to detect than traditional encryptors.

In an in-depth analysis, Sophos said that attackers would first use scanners such as Shodan or Censys to search for devices connected to the Internet using the Server Message Block (SMB) service.

Leave a Comment

Your email address will not be published. Required fields are marked *