The Cerber ransomware was mentioned for the first time in March 2016 on some Russian underground forums, on which it was offered for rent in an affiliate program. Since then, it has been spread massively via exploit kits, infecting more and more users worldwide, mostly in the APAC (Asia-Pacific) region.
Cerber
Cerber is a Windows ransomware family that emerged in 2016 and became one of the most prominent early ransomware-as-a-service operations.
Profile source: Mallory opens in a new tabCerber
Family profile
Cerber is a Windows ransomware family that emerged in 2016 and became one of the most prominent early ransomware-as-a-service operations. It was marketed through an affiliate model on Russian-language underground forums, with operators providing affiliates a management panel and taking a share of ransom revenue. Cerber was distributed at scale through exploit kits and malvertising-driven infection chains, and was also observed behind fake software-download lures and other web-based delivery flows. Campaign reporting consistently showed strong activity in the Asia-Pacific region, although infections occurred globally.
Once executed, Cerber encrypts victim files and presents multilingual extortion instructions, including localized ransom notes and desktop wallpaper changes. It has been noted for polished victim-facing workflows, including support for numerous languages and detailed payment guidance. Cerber used a combination of symmetric and asymmetric cryptography in its encryption design, including RC4 and RSA in documented versions. Later variants were described as using layered encryption approaches. Cerber also generated unique payment handling for victims and operated through dedicated payment infrastructure typical of mature ransomware operations.
Cerber incorporated multiple anti-analysis and defense-evasion measures. Documented samples terminated without encrypting when they detected malware-analysis tooling or similar analysis environments. Research also identified server-side polymorphism in Cerber delivery infrastructure, where the same download location served periodically rotated binary variants with unchanged core functionality but altered file content, complicating hash-based detection and response. Cerber was additionally associated with PowerShell-based and fileless-style delivery in some observed campaigns, and it was delivered by third-party services such as TrickGate and exploit-kit ecosystems including Magnitude.
Cerber remained influential beyond its peak operational period, appearing in later detections and serving as a design reference for subsequent ransomware families and imitators. It has also been observed in attacks following exploitation of Atlassian Confluence vulnerability CVE-2022-26134 and in reporting tied to exploitation of CVE-2023-22518. Cerber is widely regarded as a significant ransomware family in the evolution of affiliate-driven cyber extortion.
Capabilities
- Defense Evasion
- Exfiltration
- Extortion
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to Cerber
4 CVEsMITRE ATT&CK