BERT ransomware, tracked as Water Pombero, is a ransomware operation first observed in April 2025. It has targeted organizations in Asia, Europe, and the United States, including healthcare, technology, and event-services entities. BERT provides ransomware variants for Windows and Linux, including ESXi environments.
On Windows, BERT uses a PowerShell-based loader that requests elevated execution, impairs Microsoft Defender, Windows Firewall, and User Account Control protections, retrieves the ransomware payload, and executes it. The ransomware terminates processes associated with web servers, databases, and other critical services before encrypting files. Its newer Windows implementations encrypt files concurrently as they are discovered, accelerating execution across available drives.
The Linux variant supports configurable encryption paths, thread counts, and silent execution, using up to 50 threads by default. In non-silent operation, it enumerates ESXi virtual machines and forcibly terminates active virtual-machine processes before encryption, increasing operational disruption and hindering recovery. BERT uses asymmetric-key-based configuration material and delivers ransom instructions following encryption. Analysis has identified possible code reuse related to the REvil Linux variant, but no definitive relationship or geographic attribution has been established. BERT's initial-access method is not established.