logo

BERT Ransomware's First Moves: Kill the VMs, Kill the Backups

ID: 7c5946b7-0212-5899-9d59-f813aa561428

STIX ID: report--7c5946b7-0212-5899-9d59-f813aa561428

Feed Name: Halcyon Blog

Threat Score
80/100

Date Published: 2025-07-08

Date Updated: 2026-04-28

...
...

**Executive summary:** The BERT ransomware group, first observed in April 2025, targets hybrid and virtualized environments (notably VMware ESXi) across Asia, Europe, and the U.S.; its Linux variant forcibly shuts down ESXi VMs before multithreaded encryption (up to 50 threads) begins, while the Windows variant uses a PowerShell loader that escalates privileges, disables defenses, terminates critical services, and appends extensions such as ".encryptedbybert" and ".encrypted_by_bert"—posing high disruption and recovery impact to enterprise virtualized infrastructures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.