- Sophos identified a new ransomware variant called WantToCry that encrypts files remotely after exfiltration, reducing detection opportunities
- The attackers exploit exposed SMB services with weak credentials, then overwrite victim files with encrypted versions
- Ransom demands are unusually low, between $600 and $1,800, reflecting limited scope and lack of broad network impact
Security researchers Sophos observed a new ransomware variant called WantToCry which, thanks to its encryption mechanism, is a lot more difficult to spot than traditional encryptors.