bert

Malware type
ransomware
Family
Malware family
Last IoC activity
2026-07-19 04:19:06
Profile updated
2026-07-07 13:58:43

Targeted industries: healthcare-and-pharmaceutical technology-and-telecommunications media-and-entertainment

Targeted regions: country_code:us country_code:cn country_code:de

Context

BERT ransomware (also tracked as Water Pombero) first emerged in April 2025, rapidly targeting both Windows and Linux systems across Asia, Europe, and the U.S., with confirmed victims in healthcare, technology, electronics, and event services sectors. Its Windows variant employs a PowerShell-based loader that escalates privileges, disables Defender, UAC, and the firewall, then downloads the ransomware payload. The Linux version aggressively encrypts with up to 50 concurrent threads, forcibly shuts down VMware ESXi VMs to prevent recovery, and appends extensions like .encryptedbybert or .encrypted_by_bert. BERT uses AES encryption, and later variants feature optimized multithreading via ConcurrentQueue and DiskWorker threads. Analysts note code similarities with REvil and Babuk ESXi lockers, potentially pointing to shared development lineage or code reuse.

Detection coverage

  • 1 YARA rules

Detection rules

  • MALPEDIA_Win_Bert_Auto (yara-rule)

Reports & references

  • ransomlook.io — Bert (report)
  • watchguard.com — Bert (report)
  • csoonline.com — Trend Micro Flags Bert A Rapidly Growing Ransomware Threat (report)
  • securityboulevard.com — New Bert Ransomware Evolves With Multiple Variants (report)
  • halcyon.ai — Bert Ransomwares First Moves Kill The Vms Kill The Backups (report)
  • darkreading.com — Bert Blitzes Linux Windows Systems (report)
  • fortra.com — Bert Ransomware What You Need Know (report)
  • theravenfile.com — Bert Ransomware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Bert (report)
  • any.run — Bert (report)

External references