Skip to content

BERT

BERT ransomware, tracked as Water Pombero, is a ransomware operation first observed in April 2025.

Profile source: Mallory opens in a new tab

BERT

Family profile

BERT ransomware, tracked as Water Pombero, is a ransomware operation first observed in April 2025. It has targeted organizations in Asia, Europe, and the United States, including healthcare, technology, and event-services entities. BERT provides ransomware variants for Windows and Linux, including ESXi environments.

On Windows, BERT uses a PowerShell-based loader that requests elevated execution, impairs Microsoft Defender, Windows Firewall, and User Account Control protections, retrieves the ransomware payload, and executes it. The ransomware terminates processes associated with web servers, databases, and other critical services before encrypting files. Its newer Windows implementations encrypt files concurrently as they are discovered, accelerating execution across available drives.

The Linux variant supports configurable encryption paths, thread counts, and silent execution, using up to 50 threads by default. In non-silent operation, it enumerates ESXi virtual machines and forcibly terminates active virtual-machine processes before encryption, increasing operational disruption and hindering recovery. BERT uses asymmetric-key-based configuration material and delivers ransom instructions following encryption. Analysis has identified possible code reuse related to the REvil Linux variant, but no definitive relationship or geographic attribution has been established. BERT's initial-access method is not established.

Capabilities

  • Defense Evasion
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance

Operational record

11
Indicators
1
YARA rules
1
Ransom notes
1
Leak sites
0 available

Published indicators

Md5

9 total
  • 71dc9540eb03f2ed4d1b6496b13fe839
  • 00fdc504be1788231aa7b7d2d1335893
  • d1013bbaa2f151195d563b2b65126fa3
  • 3e581aad42a2a9e080a4a676de42f015
  • edec051ce461d62fbbd3abf09534b731
  • 5cab4fabffeb5903f684c936a90e0b46
  • 003291d904b89142bada57a9db732ae7
  • 29a2cc59a9ebd334103ce146bca38522
  • 38ce06bf89b28ccebf5a78404eb3818e

Ip

2 total
  • 185.100.157.74
  • 169.254.169.254

Reported operators

Threat actors

1 named in public reporting
BERT

BERT is a newly emerged ransomware group targeting both Windows and Linux platforms, with confirmed victims in Asia, Europe, and the US.

MITRE ATT&CK

BERT in ATT&CK

12 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.