BERT is an emerging ransomware operation, tracked as Water Pombero, first observed in April 2025. It has targeted organizations in Asia, Europe, and the United States, including healthcare, technology, and event-services entities. BERT deploys ransomware for Windows and Linux, including ESXi environments; its initial-access method is not confirmed.
The Windows variant terminates processes associated with web servers, databases, and other critical services before encrypting files with AES. Its execution chain has included a PowerShell-based loader that attempts elevation through PowerShell, disables Microsoft Defender, Windows Firewall protections, and User Account Control, and then retrieves and executes the ransomware payload. Newer Windows variants implement concurrent per-drive file discovery and encryption to begin locking files as they are identified.
The Linux and ESXi-oriented variant supports configurable encryption paths, thread counts, and silent operation, using up to 50 threads by default to accelerate encryption. When not operating silently, it enumerates and forcibly terminates running ESXi virtual-machine processes before encryption, increasing operational impact and hindering recovery. BERT's Linux implementation has been assessed as potentially reusing code related to a REvil Linux variant, but this does not establish a definitive operational relationship or geographic attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Storm-2570 has operated across multiple RaaS ecosystems, including Qilin, DragonForce, Anubis, and BERT.
BERT is a newly emerged ransomware group targeting both Windows and Linux platforms, with confirmed victims in Asia, Europe, and the US.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
It uses specific strings to match and terminate certain processes... associated with web servers, databases, and other critical services.
Data Destruction T1485 Windows / Linux Destroying data to prevent recovery.
Storm-2570 deploys Anubis, DragonForce, Qilin, and BERT ransomware.
It uses specific strings to match and terminate certain processes... associated with web servers, databases, and other critical services.
When executed without the command line parameters, it will proceed to shutdown virtual machines... This command will force the termination of all running virtual machine processes on the ESXi host. [The TTP table also states:] Encrypts snapshots of Virtual Machines (ESXi).
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware payload deployed by the Storm-2570 affiliate in its cross-ecosystem ransomware operations.
A ransomware family that emerged in 2025, experimenting with AI branding and sector targeting, using phishing as an initial access vector.
New ESXi-focused ransomware variant (April 2025) with capability to forcibly shut down ESXi VMs to increase impact and hinder recovery.
Bert ransomware is a new ransomware strain that uses PowerShell-based loaders, privilege escalation, and concurrent file encryption. Its Linux variant can shut down ESXi virtual machines to maximize impact.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.