cerbersyslock
- First seen
- 2017-12-01 00:00:00
- Malware type
- ransomware
- Profile updated
- 2026-07-07 13:57:14
Context
CerBerSysLock first appeared in December 2017 as a cryptoransomware imposter, leveraging Cerber-style branding to deceive victims. It uses XOR-based encryption to lock files and appends extensions such as .CerBerSysLocked0009881. Victims receive a ransom note titled “HOW TO DECRYPT FILES.txt”, which falsely claims to be from the Cerber ransomware. The note includes an email contact—[email protected]—and instructs victims to reference their ID (e.g., "CerBerSysLocked0009881") when communicating. The ransomware is technically linked to the Xorist family and is generally considered an opportunistic, low-profile scam rather than part of a broader Ransomware-as-a-Service (RaaS) operation.
Reports & references
- ransomlook.io — Cerbersyslock (report)
- 2-spyware.com — Remove Cerbersyslock Ransomware (report)