BERT is a ransomware family first observed in April 2025, with variants targeting Windows, Linux, and VMware ESXi environments. Its associated ransomware operation is tracked as Water Pombero. Confirmed victims include organizations in healthcare, technology, and event services across Asia, Europe, and the United States. The ransomware affiliate Storm-2570 has also deployed BERT alongside other ransomware families.
Windows attacks use a PowerShell loader that attempts to obtain elevated execution, disables Microsoft Defender, Windows Firewall, and User Account Control, and downloads and executes the ransomware payload. The Windows ransomware terminates processes associated with web servers, databases, and other critical services before encrypting files with AES. Earlier implementations collect target file paths before beginning multithreaded encryption; newer implementations use per-drive workers and a concurrent queue to encrypt files as they are discovered.
The Linux variant, identified in May 2025, supports configurable encryption paths, thread counts, and silent operation, with 50 encryption threads by default. It can enumerate and forcibly terminate running ESXi virtual machines before encryption, increasing disruption to virtualized workloads. Its embedded configuration contains a public key, ransom-note content, and encrypted-file extension settings. Both platform variants rename encrypted files and leave ransom notes. BERT's initial-access mechanism has not been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Analysts from Microsoft identified a consistent pattern after access was gained, even when attacks ended with Qilin, DragonForce, Anubis or BERT ransomware.
BERT is a newly emerged ransomware group targeting both Windows and Linux platforms, with confirmed victims in Asia, Europe, and the US.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
It uses specific strings to match and terminate certain processes... associated with web servers, databases, and other critical services.
Data Destruction T1485 Windows / Linux Destroying data to prevent recovery.
Storm-2570 deploys Anubis, DragonForce, Qilin, and BERT ransomware.
It uses specific strings to match and terminate certain processes... associated with web servers, databases, and other critical services.
When executed without the command line parameters, it will proceed to shutdown virtual machines... This command will force the termination of all running virtual machine processes on the ESXi host. [The TTP table also states:] Encrypts snapshots of Virtual Machines (ESXi).
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
One of the ransomware families observed at the end of Storm-2570 intrusions. The content does not provide family-specific technical details or identify which victims received this payload.
Ransomware payload deployed by the Storm-2570 affiliate in its cross-ecosystem ransomware operations.
A ransomware family that emerged in 2025, experimenting with AI branding and sector targeting, using phishing as an initial access vector.
New ESXi-focused ransomware variant (April 2025) with capability to forcibly shut down ESXi VMs to increase impact and hinder recovery.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.