Skip to content

Cerber

Cerber is a Windows ransomware family that emerged in early 2016 and became one of the most prominent early ransomware-as-a-service operations.

Profile source: Mallory opens in a new tab

Cerber

Family profile

Cerber is a Windows ransomware family that emerged in early 2016 and became one of the most prominent early ransomware-as-a-service operations. It was marketed through an affiliate model on Russian-language underground forums, with operators providing management infrastructure while affiliates handled distribution. Cerber was widely deployed worldwide, with especially heavy impact in the Asia-Pacific region, and remained notable for its scale, operational maturity, and frequent version updates.

Cerber encrypts victim files and presents multilingual extortion instructions, including localized ransom interfaces tailored to the infected system’s language. It displays ransom notes through an HTA-based interface, changes the desktop wallpaper to warn the victim, and provides payment guidance through dedicated victim portals. Public analysis has documented its use of layered cryptography involving per-file symmetric encryption protected by asymmetric keys, as well as anti-analysis behavior that suppresses malicious activity when analysis tooling or sandbox-like conditions are detected.

Distribution has been strongly associated with exploit kits and malvertising-driven infection chains, including campaigns delivered through Magnitude and other intermediary delivery services. Cerber has also been observed in user-driven download chains in which victims were lured to fake software update pages and infected after manually executing a downloaded payload. Reporting additionally links some Cerber activity to email-delivered URLs and broader ransomware affiliate ecosystems.

Cerber is also notable for server-side polymorphism. In some campaigns, the same delivery location served hash-variant samples at fixed intervals while preserving the same functional code, apparently to hinder static detection and incident response. Researchers also identified a historical flaw in Cerber’s decryption service that briefly enabled third-party recovery for some victims before the operators corrected the issue.

Cerber is widely regarded as an influential precursor to later ransomware operations. Its affiliate-driven business model, localization, anti-analysis features, and large-scale exploit-kit distribution helped shape subsequent ransomware ecosystems, and later families such as Magniber and GandCrab have been compared with or linked evolutionarily to Cerber.

Capabilities

  • Defense Evasion
  • Extortion

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 18, 2026
Last activity
Aug 18, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • NL1

Leading providers

  • TechTies Inc.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
crbr

The Cerber ransomware was mentioned for the first time in March 2016 on some Russian underground forums, on which it was offered for rent in an affiliate program. Since then, it has been spread massively via exploit kits, infecting more and more users worldwide, mostly in the APAC (Asia-Pacific) region.

Exploited software

Vulnerabilities linked to Cerber

4 CVEs

MITRE ATT&CK

Cerber in ATT&CK

28 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.