Cerber — Ransomware Profile
Cerber is a ransomware family publicly analysed by Malwarebytes in March 2016, which found it already professionally built and sold to distributors on underground Russian forums; Check Point's follow-up CerberRing research documented it as a full ransomware-as-a-service in which a developer took a cut of affiliates' campaigns. Its early distribution leaned on exploit kits, and Proofpoint recorded the Magnitude kit pushing Cerber through the then-zero-day Adobe Flash flaw CVE-2016-1019 on 2 April 2016. From the week of 20 March 2017, F5 Networks saw attacks exploiting the Apache Struts flaw CVE-2017-5638 to deliver Cerber to Windows servers. After a lull the brand resurfaced in late 2021 against internet-facing infrastructure via CVE-2021-26084 in Atlassian Confluence and CVE-2021-22205 in GitLab, but researchers assessed at the time that a new threat actor had adopted the Cerber name, ransom note and Tor payment site rather than this being the original operation: the newer encryptor uses the Crypto++ library where the original used the Windows CryptoAPI. SentinelOne, which characterises the family as a semi-private RaaS with payloads for both Linux and Windows, tracked renewed campaigns branded "C3RB3R" in the ransom note and victim portal that exploited Confluence CVE-2023-22518, and assessed those campaigns as ongoing. Cado Security Labs' April 2024 teardown of the Linux variant described a three-stage chain of UPX-packed C++ payloads that overwrites file contents in place and renames each victim file with a .L0CK3D extension. This profile therefore covers a reused brand with a discontinuous lineage rather than a single unbroken codebase.Also tracked as
C3RB3R
Vendor research
- Cerber ransomware: new, but mature Malwarebytes
- Killing a Zero-Day in the Egg: Adobe CVE-2016-1019 Proofpoint
- C3RB3R Ransomware | Ongoing Exploitation of CVE-2023-22518 Targets Unpatched Confluence Servers SentinelOne
- Cerber Ransomware: Dissecting the three heads Cado Security Labs (Darktrace)