Analysts from Microsoft identified a consistent pattern after access was gained, even when attacks ended with Qilin, DragonForce, Anubis or BERT ransomware.
BERT
BERT is a ransomware family first observed in April 2025, with variants targeting Windows, Linux, and VMware ESXi environments.
BERT
Family profile
BERT is a ransomware family first observed in April 2025, with variants targeting Windows, Linux, and VMware ESXi environments. Its associated ransomware operation is tracked as Water Pombero. Confirmed victims include organizations in healthcare, technology, and event services across Asia, Europe, and the United States. The ransomware affiliate Storm-2570 has also deployed BERT alongside other ransomware families.
Windows attacks use a PowerShell loader that attempts to obtain elevated execution, disables Microsoft Defender, Windows Firewall, and User Account Control, and downloads and executes the ransomware payload. The Windows ransomware terminates processes associated with web servers, databases, and other critical services before encrypting files with AES. Earlier implementations collect target file paths before beginning multithreaded encryption; newer implementations use per-drive workers and a concurrent queue to encrypt files as they are discovered.
The Linux variant, identified in May 2025, supports configurable encryption paths, thread counts, and silent operation, with 50 encryption threads by default. It can enumerate and forcibly terminate running ESXi virtual machines before encryption, increasing disruption to virtualized workloads. Its embedded configuration contains a public key, ransom-note content, and encrypted-file extension settings. Both platform variants rename encrypted files and leave ransom notes. BERT's initial-access mechanism has not been established.
Capabilities
- Defense Evasion
- Extortion
- Privilege Escalation
- Reconnaissance
Samples
Recent samples
2 sandbox samples in the Derp library, newest 2 shown
Reported operators
Threat actors
2 named in public reportingBERT is a newly emerged ransomware group targeting both Windows and Linux platforms, with confirmed victims in Asia, Europe, and the US.
MITRE ATT&CK