BERT Ransomware Group Targets Asia and Europe on Multiple Platforms
A newly emerged ransomware group called BERT has been targeting organizations across Asia and Europe since April. The group employs simple code with effective execution, impacting sectors such as healthcare, technology, and event services. BERT's ransomware operates on both Windows and Linux platforms, using PowerShell-based loaders, privilege escalation, and concurrent file encryption. On Linux systems, it can support up to 50 threads for fast encryption and forcibly shut down ESXi virtual machines. The group's tactics include disabling security features, terminating specific processes, and using standard encryption algorithms. BERT's variants have evolved, streamlining their encryption process and expanding their targeting activities. The Linux variant shows similarities to the REvil ransomware, suggesting possible code reuse.
Pulse ID: 686bb6597ce02f8f4a33b453
Pulse Link: https://otx.alienvault.com/pulse/686bb6597ce02f8f4a33b453
Pulse Author: AlienVault
Created: 2025-07-07 11:58:17
Be advised, this data is unverified and should be considered preliminary. Always do further verification.