Last seven days
- First activity
- Sep 30, 2026
- Last activity
- Sep 30, 2026
- Feed role
- Distribution
- Host form
- 0 IP / 1 hostnames
Cerber is a Windows ransomware family that emerged in 2016 and became one of the most prominent early ransomware-as-a-service operations.
Profile source: Mallory opens in a new tabCerber
Cerber is a Windows ransomware family that emerged in 2016 and became one of the most prominent early ransomware-as-a-service operations. It was marketed through an affiliate model on Russian-language underground forums, with operators providing affiliates a management panel and taking a share of ransom revenue. Cerber was distributed at scale through exploit kits and malvertising-driven infection chains, and was also observed behind fake software-download lures and other web-based delivery flows. Campaign reporting consistently showed strong activity in the Asia-Pacific region, although infections occurred globally.
Once executed, Cerber encrypts victim files and presents multilingual extortion instructions, including localized ransom notes and desktop wallpaper changes. It has been noted for polished victim-facing workflows, including support for numerous languages and detailed payment guidance. Cerber used a combination of symmetric and asymmetric cryptography in its encryption design, including RC4 and RSA in documented versions. Later variants were described as using layered encryption approaches. Cerber also generated unique payment handling for victims and operated through dedicated payment infrastructure typical of mature ransomware operations.
Cerber incorporated multiple anti-analysis and defense-evasion measures. Documented samples terminated without encrypting when they detected malware-analysis tooling or similar analysis environments. Research also identified server-side polymorphism in Cerber delivery infrastructure, where the same download location served periodically rotated binary variants with unchanged core functionality but altered file content, complicating hash-based detection and response. Cerber was additionally associated with PowerShell-based and fileless-style delivery in some observed campaigns, and it was delivered by third-party services such as TrickGate and exploit-kit ecosystems including Magnitude.
Cerber remained influential beyond its peak operational period, appearing in later detections and serving as a design reference for subsequent ransomware families and imitators. It has also been observed in attacks following exploitation of Atlassian Confluence vulnerability CVE-2022-26134 and in reporting tied to exploitation of CVE-2023-22518. Cerber is widely regarded as a significant ransomware family in the evolution of affiliate-driven cyber extortion.
Samples
57eed34bd2d5de4d4efedd1bf4487ca21987775130c0aefba1fc9cba04c8f780 6422f5468473875d3b241c0a68090c83f3d6e398fb53b83853bc95ece0c3de31 8261e5a060b5efc80117603a1cbe2aa80cb647b52930c2d146132ecfc5aea91a 84499bf8af22cde94ee1c254d184df10bfcbf12fdaad7860950e8ba4face0e6b c05b668f1ba8897a9fe6345b627d696897f4dc6817dc2410600940d25102d740 Reported operators
The Cerber ransomware was mentioned for the first time in March 2016 on some Russian underground forums, on which it was offered for rent in an affiliate program. Since then, it has been spread massively via exploit kits, infecting more and more users worldwide, mostly in the APAC (Asia-Pacific) region.
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.