216.73.216.6

Exposed SMB: The Hidden Risk Behind 'WantToCry' Ransomware Attacks

· Published 31/01/2025 13:25 · Modified 31/01/2025 14:07

Export JSON

Essential information

Published
31/01/2025 13:25
Modified
31/01/2025 14:07
Tags
2025-01-31 ransomware smb wanttocry
Related entities
2 observables, 1 intrusion sets (apt), 9 techniques (mitre), 1 malware

Description

The group, active since December 2023, has intensified its operations in 2024 by exploiting misconfigured Server Message Block () services. The group targets multiple network services, including , SSH, FTP, RPC, and VNC, using brute-force attacks with a database of over one million passwords. Once access is gained, the encrypts publicly exposed network drives and NAS devices, appending the extension '.want_to_cry' to affected files. The attackers communicate with victims through encrypted messaging platforms and demand ransom payments. The 's execution flow includes reconnaissance, exploitation via brute force, accessing shared drives, and payload execution without leaving local artifacts. To mitigate risks, organizations should implement security measures such as regular antivirus updates, disabling unnecessary sharing, requiring authentication, restricting public access, and enabling advanced detection systems.

External references