bert
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-19 04:19:06
- Profile updated
- 2026-07-07 13:58:43
Targeted industries: healthcare-and-pharmaceutical technology-and-telecommunications media-and-entertainment
Targeted regions: country_code:us country_code:cn country_code:de
Context
BERT ransomware (also tracked as Water Pombero) first emerged in April 2025, rapidly targeting both Windows and Linux systems across Asia, Europe, and the U.S., with confirmed victims in healthcare, technology, electronics, and event services sectors. Its Windows variant employs a PowerShell-based loader that escalates privileges, disables Defender, UAC, and the firewall, then downloads the ransomware payload. The Linux version aggressively encrypts with up to 50 concurrent threads, forcibly shuts down VMware ESXi VMs to prevent recovery, and appends extensions like .encryptedbybert or .encrypted_by_bert. BERT uses AES encryption, and later variants feature optimized multithreading via ConcurrentQueue and DiskWorker threads. Analysts note code similarities with REvil and Babuk ESXi lockers, potentially pointing to shared development lineage or code reuse.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Bert_Auto (yara-rule)
Reports & references
- ransomlook.io — Bert (report)
- watchguard.com — Bert (report)
- csoonline.com — Trend Micro Flags Bert A Rapidly Growing Ransomware Threat (report)
- securityboulevard.com — New Bert Ransomware Evolves With Multiple Variants (report)
- halcyon.ai — Bert Ransomwares First Moves Kill The Vms Kill The Backups (report)
- darkreading.com — Bert Blitzes Linux Windows Systems (report)
- fortra.com — Bert Ransomware What You Need Know (report)
- theravenfile.com — Bert Ransomware (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Bert (report)
- any.run — Bert (report)