‘Detection surface is significantly reduced’: Sophos report warns new ‘WantToCry’ ransomware could pose a major risk to your business, here’s what we know


  • Sophos identified a new ransomware variant called WantToCry that remotely encrypts files after exfiltration, reducing detection opportunities
  • The attackers exploit exposed SMB services with weak credentials and then overwrite victim files with encrypted versions
  • Ransom demands are unusually low, between $600 and $1,800, reflecting limited scale and lack of broad network influence

Security researchers Sophos observed a new ransomware variant called WantToCry, which, thanks to its encryption mechanism, is much harder to spot than traditional encryptions.

In an in-depth analysis, Sophos said the attackers would first use scanners such as Shodan or Censys to look for Internet-connected devices using the Server Message Block (SMB) service.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top