Cerber is a Windows ransomware family that emerged in 2016 and became one of the most prominent early ransomware-as-a-service operations. It was marketed through an affiliate model on Russian-language underground forums, with operators providing affiliates a management panel and taking a share of ransom revenue. Cerber was distributed at scale through exploit kits and malvertising-driven infection chains, and was also observed behind fake software-download lures and other web-based delivery flows. Campaign reporting consistently showed strong activity in the Asia-Pacific region, although infections occurred globally.
Once executed, Cerber encrypts victim files and presents multilingual extortion instructions, including localized ransom notes and desktop wallpaper changes. It has been noted for polished victim-facing workflows, including support for numerous languages and detailed payment guidance. Cerber used a combination of symmetric and asymmetric cryptography in its encryption design, including RC4 and RSA in documented versions. Later variants were described as using layered encryption approaches. Cerber also generated unique payment handling for victims and operated through dedicated payment infrastructure typical of mature ransomware operations.
Cerber incorporated multiple anti-analysis and defense-evasion measures. Documented samples terminated without encrypting when they detected malware-analysis tooling or similar analysis environments. Research also identified server-side polymorphism in Cerber delivery infrastructure, where the same download location served periodically rotated binary variants with unchanged core functionality but altered file content, complicating hash-based detection and response. Cerber was additionally associated with PowerShell-based and fileless-style delivery in some observed campaigns, and it was delivered by third-party services such as TrickGate and exploit-kit ecosystems including Magnitude.
Cerber remained influential beyond its peak operational period, appearing in later detections and serving as a design reference for subsequent ransomware families and imitators. It has also been observed in attacks following exploitation of Atlassian Confluence vulnerability CVE-2022-26134 and in reporting tied to exploitation of CVE-2023-22518. Cerber is widely regarded as a significant ransomware family in the evolution of affiliate-driven cyber extortion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Atlassian confirmed that threat actors are now actively exploiting a recently disclosed critical Atlassian Confluence vulnerability. The exploited vulnerability, CVE-2023-22518 (CVSS: 10), is tracked as an Improper Authorization vulnerability in Confluence Data Center and Servers. Exploitation of this vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. | Multiple security organizations have identified Cerber ransomware following exploitation of CVE-2023-22518.
CVE-2016-7255 Classification: 0-Day Basic Description: Memory corruption in NtUserSetWindowLongPtr ... Found in the following Malware samples: Attributed to APT28 (aka Fancy Bear, Sednit). Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze | Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze
One recent remote code execution vulnerability, CVE-2022-26134, targets Confluence versions 1.3.0-7.4.17, 7.13.0-7.13.7, 7.14.0-7.14.3, 7.15.0-7.15.2, 7.16.0-7.16.4, 7.17.0-7.17.4 and 7.18.0-7.18.1. We have observed successful exploitation leveraging this vulnerability to perform Cerber Ransomware attacks. | We have observed successful exploitation leveraging this vulnerability to perform Cerber Ransomware attacks.
CVE-2019–1367 enables Remote Code Execution (RCE) in the context of Internet explorer in all version from 8, 9, 10 and 11 due to a memory corruption in jscript.dll... Google TAG Team discovered CVE-2019–1367 exploited in the wild by a threat actor.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Cerber ransomware was mentioned for the first time in March 2016 on some Russian underground forums, on which it was offered for rent in an affiliate program. Since then, it has been spread massively via exploit kits, infecting more and more users worldwide, mostly in the APAC (Asia-Pacific) region.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
ユーザーがそのURLをクリックすると、(弊社が確認したケースでは)以下のような「Google Chrome」のダウンロードサイトの偽サイトが表示されます。そして自動的にファイルのダウンロードが促されます。
主にメール等でURLが送付され、ユーザーがそのURLをクリックすると、(弊社が確認したケースでは)以下のような「Google Chrome」のダウンロードサイトの偽サイトが表示されます。
The original decryptor was dirty patched to use the same SIGN as was previously paid.
Many fileless malware embed malicious PowerShell scripts whose commands are often the ones responsible for downloading and launching or executing the payload.
その結果、「Cerber」のバイナリは動作に関わるコード領域はハッシュ値が異なる検体であっても同一であり、バイナリの末尾に毎回異なるランダムと思われるデータが付与されているだけであることがわかりました。
今回のようにサーバサイド側でダウンロードさせるマルウェアを多様に変化(ポリモーフィズム)させ、同一URLから異なる検体が時折またはアクセスする度にダウンロードされる仕組みを「サーバサイドポリモーフィズム」と呼びます。
The main payload of the loader is the injection of code in another process. In this case, the injected code is the whole Cerber binary...
This loader is designed to hollow out a normal process where the code of CERBER is instead run.
when encrypting files FuxSocy will skip files whose file path contain certain strings.
Blockchain-based C&C is the next step in a long evaluation of criminal TTPs, but it will be very difficult to mitigate this technique in the future
The first message contains only the machine ID, which is sent using the following format: "sign=%s" % SIGN ... The CAPTCHA solution, together with PRIVATE_KEY and SIGN, are sent to the server using the following format: "captcha=%d&sign=%s&private_key=%s" % (CAPTCHA, SIGN, PRIVATE_KEY)
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
50 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family described here as an early adopter of blockchain-derived command-and-control, generating dynamic C2 domains from Bitcoin transaction hashes.
A ransomware family mentioned as one of the payloads delivered by Magnitude Exploit Kit.
A ransomware-as-a-service platform cited as an early pioneer of the RaaS model.
Ransomware family referenced as an example of recognized ransomware strains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.