Security5.01.2026

Hacker rescues South African pharmacy from cyber attack

An independent family-owned pharmacy in Cape Town was recently spared a devastating start to the year thanks to the diligence of cybersecurity forensic investigator Bruce Malaudzi.

Malaudzi had stumbled upon something extremely rare — a vulnerable server in the midst of suffering a ransomware attack.

Like spotting a Gaboon viper under a pile of leaves that is busy digesting its recently caught prey, he had discovered the system as the malware was infecting it.

“Part of my job is threat hunting,” Malaudzi told MyBroadband. “While hunting for threats through Shodan, I came across a Windows server that was directly accessible to the Internet.”

Shodan is a search engine of Internet-connected devices. Often referred to as the search engine for hackers, it lets users query openly available information about any device with a public IP address.

Malaudzi found a server which Shodan reported was vulnerable to a five-year-old remote code execution vulnerability called CVE-2020-0796.

The vulnerability exists in unpatched versions of Microsoft Server Message Block 3.1.1 (SMBv3), the file-sharing protocol used by Windows.

Worse still, Windows file sharing was enabled on the server’s root drives with no password set for the root account.

Malaudzi said he first discovered the vulnerable system during the day on Friday, but there were no signs then that it was infected with ransomware.

In fact, he initially dismissed the server as a honeypot —  a decoy system designed to attract and trap cyber attackers.

However, when Malaudzi returned to the server later, he found that some of the file names had changed, with the extension “.want_to_cry” appended to many of them.

A text file containing the ransom note, called “!want_to_cry.txt”, was also placed in a subfolder on the file system demanding $600 (R10,135) for a decryption key.

Malaudzi saw file names changing before his eyes as he traversed the system, further indicating that the ransomware was busy running its encryption routine at that very moment.

Working as quickly as he could, Malaudzi searched through the system to find information about the attack and its target, in the hopes of warning the victim.

He found invoice files that had not yet been encrypted, which led him to the name of the business being targeted — Constantia Pharmacy, located on Spaanschemat River Road in Cape Town.

Other files and folders on the system also suggested that he was looking at a server built to manage a pharmacy, including the name “RxWin” and a database file with “Pharm” in its name.

By this point, it was long after hours. Malaudzi wrote an email explaining the situation to MyBroadband, sending it at 04:00 on Saturday, 3 January 2026.

Mounting a rescue

The information on Shodan about Constantia Pharmacy’s exposed Windows-based PropPharm RxWin server

MyBroadband saw Malaudzi’s email just after 07:00 on Saturday and immediately began verifying his information to contact the pharmacy.

Unfortunately, there was no answer at the pharmacy’s publicly available telephone numbers at 07:24, but we called back at 08:30 when it opened.

After convincing the pharmacist on duty that we were not scammers, we were put in contact with Tessa Wood, the daughter of Noel Wood, who founded the Constantia Pharmacy in 1968.

Wood asked us to call the company that supplies its pharmacy management system, ProPharm, to relay the necessary information directly.

ProPharm, which is owned by the ComputAssist Group, develops the RxWin and RxPRO pharmacy management systems.

To its credit, ProPharm took immediate action, helping to rescue its customer’s data and avoid a costly outage due to the ransomware attack.

Want_to_cry modus operandi

Want_to_cry ransom note

Little is known about the group behind Want_to_cry. However, Quick Heal Technologies’ enterprise security arm, Seqrite, believes the gang has been active since December 2023.

The Internet is also littered with reports from self-hosting hobbyists and other individual users who found their personal file servers infected with the ransomware.

According to Seqrite, the group uses brute force attacks against exposed systems to compromise servers with weak passwords or default credentials.

Once access is gained, the ransomware remotely encrypts publicly exposed network drives and network-attached storage devices. The attacker leaves behind a ransom note containing details about payment.

The group does not appear to have a leak site on either the regular clear web or dark web. Therefore, it purely tries to extort money by locking people out of their files.

MyBroadband asked ProPharm and ComputAssist for comment about the attack and why the SMB shares of Constantia Pharmacy’s RxWin server were publicly accessible with no root password set.

Neither company responded by publication. This article will be updated with their statement should they provide feedback.

Show comments

Latest news

More news

Trending news

Poll

What gaming subscription services do you use?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter