logo

Cerber2021 Ransomware Back in Action

ID: 31cced0f-7833-5c5a-96ed-4b649cb91eea

STIX ID: report--31cced0f-7833-5c5a-96ed-4b649cb91eea

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

This report provides a technical analysis of Cerber2021 ransomware—covering a 32-bit Windows executable and a 64-bit UPX-packed Linux ELF—describing how actors exploit Confluence and GitLab vulnerabilities to deliver the ransomware, the encryption behavior (files on drives C:–Z: or Linux drives are encrypted and appended with ".locked"), use of the Crypto++ library, Tor-based payment infrastructure and ransom note, sample hashes and IOCs, and recommended mitigations (patching, backups, AV).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.