Cerber Ransomware

Description Summary

Cerber was a dominant ransomware-as-a-service of 2016–2017, distributed at scale via exploit kits (RIG, Neutrino), malvertising, and spam. It was notable for a text-to-speech ('voice') ransom notification and heavily obfuscated payloads, and for excluding former-Soviet-state systems. Its RaaS model let affiliates keep a share of ransoms.

Threat Actor

RaaS operators (Russian-speaking); mass-distributed via exploit kits, malvertising, and spam.

Technical Indicators

Encryption Extension
.cerber / .cerber2 / .cerber3 / random 4-char (later versions)
Encryption Algorithm
AES-256 (files) + RSA-2048 (key wrapping); RC4 in components
Ransom Note Name
# DECRYPT MY FILES #.txt / .html / .vbs (with an audio message)
Targeted Industries
Cross-sector (consumer and enterprise)
First Seen
March 2016
Last Seen
~2017 (declined)
Geographical Location
Worldwide (excludes CIS)

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 2 T1566 Phishing
T1189 Drive-by Compromise (exploit kits)
Execution x 1 T1204 User Execution
Defense Evasion x 2 T1497 Virtualization/Sandbox Evasion
T1027 Obfuscated Files or Information
Impact x 2 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery