Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 20, 2026 (about 3 months ago).

people · May 20, 2026

Sophos Identifies WantToCry Ransomware Using Remote SMB Encryption

Share the canonical public link.

Share as image

Sophos Counter Threat Unit identified WantToCry ransomware that uses SMB brute-force for access and remote encryption on May 19, 2026. The variant exfiltrates files for encryption on attacker infrastructure then rewrites encrypted files back via SMB with a $600 ransom demand. Sophos CryptoGuard detected the activity on a WIN-J9D866ESIJ2 host from January 6, 2026. Shodan scans as of January 7, 2026 showed over 1.5 million exposed SMB devices. WannaCry from 2017 used a similar SMB exposure vector.

Below validation threshold — auto-passed without scoring

Supporting evidence