cerbersyslock

First seen
2017-12-01 00:00:00
Malware type
ransomware
Profile updated
2026-07-07 13:57:14

Context

CerBerSysLock first appeared in December 2017 as a cryptoransomware imposter, leveraging Cerber-style branding to deceive victims. It uses XOR-based encryption to lock files and appends extensions such as .CerBerSysLocked0009881. Victims receive a ransom note titled “HOW TO DECRYPT FILES.txt”, which falsely claims to be from the Cerber ransomware. The note includes an email contact—[email protected]—and instructs victims to reference their ID (e.g., "CerBerSysLocked0009881") when communicating. The ransomware is technically linked to the Xorist family and is generally considered an opportunistic, low-profile scam rather than part of a broader Ransomware-as-a-Service (RaaS) operation.

Reports & references

  • ransomlook.io — Cerbersyslock (report)
  • 2-spyware.com — Remove Cerbersyslock Ransomware (report)

External references