BERT RANSOMWARE
ID: fd674760-88e1-5901-ae97-c109bfa6b6cb
STIX ID: report--fd674760-88e1-5901-ae97-c109bfa6b6cb
Feed Name: THE RAVEN FILE
Threat Score
**BERT Ransomware — Initial Investigation (Mar–May 2025):** This report documents the emergence of the BERT ransomware group targeting Windows (initially) and later Linux systems via phishing and a PowerShell-based loader that disables security controls and fetches a payload; it includes technical analysis of encryption methods, sample filenames and timestamps, TOR data-leak sites, hosting/IP ownership details, and links to collected IOCs and samples.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
