“Detection surface area is significantly reduced”: Sophos report warns new “WantToCry” ransomware could pose major risk to your business. Here’s what we know


  • Sophos has identified a new ransomware variant called WantToCry that encrypts files remotely after exfiltration, reducing opportunities for detection.
  • Attackers exploit exposed SMB services with weak credentials and then overwrite victims’ files with encrypted versions.
  • Ransom demands are unusually low, between $600 and $1,800, reflecting limited reach and a lack of large-scale network impact.

Sophos security researchers have observed a new ransomware variant called WantToCry that, thanks to its encryption mechanism, is much harder to spot than traditional encryptors.

In an in-depth analysis, Sophos said attackers would first use scanners such as Shodan or Censys to search for internet-connected devices using the Server Message Block (SMB) service.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top