WantToCry is a ransomware_group tracked by ThreatCluster, appearing in 2 threat clusters built from 7 intelligence report mentions.
WantToCry is a ransomware_group tracked across 2 threat clusters and 7 intelligence report mentions on ThreatCluster. First observed February 5, 2026; most recent activity May 21, 2026.
The WantToCry ransomware campaign exploits exposed Server Message Block (SMB) services to remotely encrypt files without deploying malware on victim systems. Attackers scan for open SMB ports and use brute-force methods…
Ransomware operators are leveraging virtual machines (VMs) provided by ISPsystem to host and distribute malicious payloads. Cybersecurity researchers at Sophos identified this tactic during their investigation of recent…
WantToCry is a ransomware_group tracked by ThreatCluster, appearing in 2 threat clusters built from 7 intelligence report mentions.
The most recent intelligence report mentioning WantToCry on ThreatCluster is dated May 21, 2026. Activity was first observed February 5, 2026, giving a tracked span from then to May 21, 2026.
Across ThreatCluster reporting, WantToCry most frequently co-occurs with Brute Force, Ransomware, Germany, Russia, Singapore, among 12 tracked related entities.
The most significant recent cluster is “WantToCry Ransomware Campaign Targets Exposed SMB Services for Remote Encryption” (6 articles · Updated May 20, 2026). WantToCry appears across 2 threat clusters in total, listed above with sources.
WantToCry appears in 7 intelligence report mentions across 2 deduplicated threat clusters, aggregated from 17,000+ monitored sources.