Cerber is a Windows ransomware family that emerged in early 2016 and became one of the most prominent early ransomware-as-a-service operations. It was marketed through an affiliate model on Russian-language underground forums, with operators providing management infrastructure while affiliates handled distribution. Cerber was widely deployed worldwide, with especially heavy impact in the Asia-Pacific region, and remained notable for its scale, operational maturity, and frequent version updates.
Cerber encrypts victim files and presents multilingual extortion instructions, including localized ransom interfaces tailored to the infected system’s language. It displays ransom notes through an HTA-based interface, changes the desktop wallpaper to warn the victim, and provides payment guidance through dedicated victim portals. Public analysis has documented its use of layered cryptography involving per-file symmetric encryption protected by asymmetric keys, as well as anti-analysis behavior that suppresses malicious activity when analysis tooling or sandbox-like conditions are detected.
Distribution has been strongly associated with exploit kits and malvertising-driven infection chains, including campaigns delivered through Magnitude and other intermediary delivery services. Cerber has also been observed in user-driven download chains in which victims were lured to fake software update pages and infected after manually executing a downloaded payload. Reporting additionally links some Cerber activity to email-delivered URLs and broader ransomware affiliate ecosystems.
Cerber is also notable for server-side polymorphism. In some campaigns, the same delivery location served hash-variant samples at fixed intervals while preserving the same functional code, apparently to hinder static detection and incident response. Researchers also identified a historical flaw in Cerber’s decryption service that briefly enabled third-party recovery for some victims before the operators corrected the issue.
Cerber is widely regarded as an influential precursor to later ransomware operations. Its affiliate-driven business model, localization, anti-analysis features, and large-scale exploit-kit distribution helped shape subsequent ransomware ecosystems, and later families such as Magniber and GandCrab have been compared with or linked evolutionarily to Cerber.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CERBER https://www.trendmicro.com/ja_jp/research/23/l/cerber-ransomware-exploits-cve-2023-22518.html
CVE-2016-7255 Classification: 0-Day Basic Description: Memory corruption in NtUserSetWindowLongPtr ... Found in the following Malware samples: Attributed to APT28 (aka Fancy Bear, Sednit). Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze | Used later by Ursnif, Dreambot, GandCrab, Cerber, Maze
One recent remote code execution vulnerability, CVE-2022-26134, targets Confluence versions 1.3.0-7.4.17, 7.13.0-7.13.7, 7.14.0-7.14.3, 7.15.0-7.15.2, 7.16.0-7.16.4, 7.17.0-7.17.4 and 7.18.0-7.18.1. We have observed successful exploitation leveraging this vulnerability to perform Cerber Ransomware attacks. | We have observed successful exploitation leveraging this vulnerability to perform Cerber Ransomware attacks.
CVE-2019–1367 enables Remote Code Execution (RCE) in the context of Internet explorer in all version from 8, 9, 10 and 11 due to a memory corruption in jscript.dll... Google TAG Team discovered CVE-2019–1367 exploited in the wild by a threat actor.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Cerber ransomware was mentioned for the first time in March 2016 on some Russian underground forums, on which it was offered for rent in an affiliate program. Since then, it has been spread massively via exploit kits, infecting more and more users worldwide, mostly in the APAC (Asia-Pacific) region.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
ユーザーがそのURLをクリックすると、(弊社が確認したケースでは)以下のような「Google Chrome」のダウンロードサイトの偽サイトが表示されます。そして自動的にファイルのダウンロードが促されます。
主にメール等でURLが送付され、ユーザーがそのURLをクリックすると、(弊社が確認したケースでは)以下のような「Google Chrome」のダウンロードサイトの偽サイトが表示されます。
The original decryptor was dirty patched to use the same SIGN as was previously paid.
Many fileless malware embed malicious PowerShell scripts whose commands are often the ones responsible for downloading and launching or executing the payload.
その結果、「Cerber」のバイナリは動作に関わるコード領域はハッシュ値が異なる検体であっても同一であり、バイナリの末尾に毎回異なるランダムと思われるデータが付与されているだけであることがわかりました。
今回のようにサーバサイド側でダウンロードさせるマルウェアを多様に変化(ポリモーフィズム)させ、同一URLから異なる検体が時折またはアクセスする度にダウンロードされる仕組みを「サーバサイドポリモーフィズム」と呼びます。
The main payload of the loader is the injection of code in another process. In this case, the injected code is the whole Cerber binary...
This loader is designed to hollow out a normal process where the code of CERBER is instead run.
when encrypting files FuxSocy will skip files whose file path contain certain strings.
Blockchain-based C&C is the next step in a long evaluation of criminal TTPs, but it will be very difficult to mitigate this technique in the future
The first message contains only the machine ID, which is sent using the following format: "sign=%s" % SIGN ... The CAPTCHA solution, together with PRIVATE_KEY and SIGN, are sent to the server using the following format: "captcha=%d&sign=%s&private_key=%s" % (CAPTCHA, SIGN, PRIVATE_KEY)
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
49 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family described here as an early adopter of blockchain-derived command-and-control, generating dynamic C2 domains from Bitcoin transaction hashes.
A ransomware family mentioned as one of the payloads delivered by Magnitude Exploit Kit.
A ransomware-as-a-service platform cited as an early pioneer of the RaaS model.
Ransomware family referenced as an example of recognized ransomware strains.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.