Description Summary
Cerber was a dominant ransomware-as-a-service of 2016–2017, distributed at scale via exploit kits (RIG, Neutrino), malvertising, and spam. It was notable for a text-to-speech ('voice') ransom notification and heavily obfuscated payloads, and for excluding former-Soviet-state systems. Its RaaS model let affiliates keep a share of ransoms.
Threat Actor
RaaS operators (Russian-speaking); mass-distributed via exploit kits, malvertising, and spam.
Technical Indicators
Encryption Extension
.cerber / .cerber2 / .cerber3 / random 4-char (later versions)
Encryption Algorithm
AES-256 (files) + RSA-2048 (key wrapping); RC4 in components
Ransom Note Name
# DECRYPT MY FILES #.txt / .html / .vbs (with an audio message)
Targeted Industries
Cross-sector (consumer and enterprise)
First Seen
March 2016
Last Seen
~2017 (declined)
Geographical Location
Worldwide (excludes CIS)
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 2 | T1566 | Phishing |
| T1189 | Drive-by Compromise (exploit kits) | |
| Execution x 1 | T1204 | User Execution |
| Defense Evasion x 2 | T1497 | Virtualization/Sandbox Evasion |
| T1027 | Obfuscated Files or Information | |
| Impact x 2 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery |