Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Cerber

100
Global rank
105 infographic chevron month
Month rank
76 infographic chevron week
Week rank
0
IOCs

Cerber is a Ransomware-as-a-Service (RaaS) that appeared in 2016, spread quickly and has been evolving since. It became well-known for its file encryption, offline capabilities, and sophisticated evasion techniques. It primarily targets enterprises, financial institutions, and government entities, encrypting their data and demanding ransom payments in Bitcoin. It also targets everyday users encrypting personal files (photos, documents) with the risk of their permanent loss.

Ransomware
Type
Unknown
Origin
1 February, 2016
First seen
14 September, 2026
Last seen

How to analyze Cerber with ANY.RUN

Type
Unknown
Origin
1 February, 2016
First seen
14 September, 2026
Last seen

IOCs

IP addresses
91.121.217.200
91.121.218.6
91.121.217.9
91.121.217.49
91.121.218.118
91.121.217.114
91.121.216.84
91.120.216.16
91.121.219.223
91.121.219.35
91.121.216.153
91.120.216.19
91.121.218.220
91.121.219.214
91.121.216.18
91.121.217.110
91.121.217.244
91.121.218.88
91.121.216.124
91.121.219.92
Hashes
b04036e4c638f832bdb553a11d740d76bc1cb7148f163856239c9f51943be352
d2bb091268ade68ad8121d2184d0fbce128070156304bd4de312e6fbd267409c
c75e12977a9d2903bf675799dda966ce5c8322df3a09050a619dab1e1243e679
2a6033206477d075a81adbf16fa97760b4ebfb2e9d4c5ad395e40c8ee78e7f96
6f7bfa4789bd506ccf81640feec036bac7c0354084ca472f55a79ce53b9c3ade
529d930b25a3b6e2af851a89de00b77c52f7f9c7a35000cb4f0f415f4e101bda
8a5148b9041b71254969b8c039f57bdf022333a677307aba885656d790bf2025
fd46c0f8d635784d695fd724121d628558d9d2346b6daa822d00c2d48f9a4b34
e16d4df683d15fa6241edff75d1d51d3ed1ff1b6e265dd78dd33f64702620ca4
80d5c251914179ce67d9915bb4fdc1d46359c57974eedb6f99bb4fbb111480c5
764f92122df2bb2f7325be486684bc4d74f0c49aa541865c07c668d036151ff8
2a923595c1145d00bb67a06282b245abd3341a95fbbace1ce83643a500d78dd2
d10d8b8b86103e0382e45f6e6a2e038c49a2c68fc6bf2ee0a31cac62e95850d4
d8550468365785faa148ec68582aaa8bb53b4771c027f72aa2245f4f5d5b646c
f366224050cfc8b9a477c5650cff78a401aafd8838e48ae92322afaea417dc61
52c8bf7e107e96f76239d513a542d207652d07a0d564ea7735da15acc6775be7
fb0c80972bd71f44d68e5310290ae598f2a72c7fdd91fb236d8f93d6345201b7
5dc6991172e52eff196bbb568896157646fbeda7c3f974bdc3f9d4797d344a88
9b626d9da2d25101ede338c4fb71fa0dc1cd61680ddf6bad04122fd0c2b9b6c8
5e5403c895200122292c7a4c3e7d2dff342b8063cf93aee310bb905ae88fb249
Domains
settings-win.data.microsoft.com
c.pki.goog
www.bing.com
ecs.office.com
chain.so
fe3cr.delivery.mp.microsoft.com
ocsp.digicert.com
api.blockcypher.com
nexusrules.officeapps.live.com
crl.microsoft.com
slscr.update.microsoft.com
client.wns.windows.com
self.events.data.microsoft.com
login.live.com
google.com
activation-v2.sls.microsoft.com
oneocsp.microsoft.com
bitaps.com
www.microsoft.com
go.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://www.bing.com/dsb/scenario?name=trendingsearchwithcache&cc=us&setlang=en-us
https://www.bing.com/dsb/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=us&setlang=en-us&clientdatetime=9%2f14%2f2026%2c%207%3a23%3a39%20pm
https://www.bing.com/threshold/xls.aspx?t=5&dl=1&f=9&wsbc=1
https://www.bing.com/th?id=odswg.2fe129d9-0a1b-4c02-9807-00f83b7e0075&pid=dsb
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=n&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=1&cvid=d24450746504424293736b3ad7fcf5e8&ig=2bbc229f3abe4341ab91bdc7c01902dc
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=not&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=3&cvid=d24450746504424293736b3ad7fcf5e8&ig=f40cd9875ba4453cbc3611386e87330f
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=no&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=2&cvid=d24450746504424293736b3ad7fcf5e8&ig=b2171aed15554e0e9fde1b8dd19268d5
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=note&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=4&cvid=d24450746504424293736b3ad7fcf5e8&ig=8d39d8811dca468c960685cb021ec4ee
https://www.bing.com/th?id=osk.ac436f082f306a91af11103bd0abbc9d&w=80&h=80&qlt=90&c=6&rs=1&cdv=1&pid=rs
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=notep&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=5&cvid=d24450746504424293736b3ad7fcf5e8&ig=f1c45bf679274e1f97a4576a33c7daf4
https://www.bing.com/as/api/windowscortanapane/v2/suggestions?qry=notepa&setlang=en-us&cc=us&nohs=1&qfm=1&seahisoff=1&cp=6&cvid=d24450746504424293736b3ad7fcf5e8&ig=91b3f95f2e044b5ea85561da028d49df
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://www.bing.com/web/xlsc.aspx?t=5&dl=1&f=9&wsbc=1
https://login.live.com/rst2.srf
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 4780
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 9604
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 11523
comments 0

What is Cerber malware?

Cerber is a Ransomware-as-a-service that does not require an attacker to be a skilled hacker to deploy it. Since its debut in 2016, it has been frequently updated to bypass signature-based detections.

It mostly arrives at the target network via phishing emails with malicious attachments (zipped .DOT files, Windows Script Files [WSF], or self-extracting archives). Some campaigns include password-protected attachments with the password provided in the email to bypass basic email filters.

Once inside a network, Cerber typically waits for an opportune moment (e.g., system reboot or user idle time) to execute, increasing its chances of going unnoticed initially. Then the malware scans local and network drives for specific file types (documents, databases, media). It encrypts the found files using AES-256 and RSA-2048 encryption.

Cerber ransomware analysis in the ANY.RUN Sandbox Analysis of Cerber Ransomware in the ANY.RUN sandbox

It deletes shadow copies of the decrypted files and disables recovery options; after the operations are finished, Cerber generates a ransom note and deletes its executable to minimize forensic evidence.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Cerber’s technical details

Cerber is equipped with advanced capabilities as it:

  • Creates scheduled tasks and registry modifications to ensure persistence.
  • Drops multiple copies of itself in %AppData%, %Temp%, or %LocalAppData%.
  • Scans local and network drives for data files and encrypts them with AES-256 and RSA-2048 algorithms.
  • Drops a ransom note (README.hta) in affected folders with instructions to pay in Bitcoin via a Tor-based payment portal. Some variants use voice-based ransom notes, playing an audio message demanding payment.
  • Uses PowerShell scripts and scheduled tasks to execute itself remotely.
  • Attempts to spread via SMB shares, infecting additional network points.
  • Cerber employs a number of advanced evasion tactics: code obfuscation, sandbox detection, dynamic domain generation, fileless execution (some strains use PowerShell scripts to execute directly in memory). It can encrypt files without an internet connection, preventing detection via network traffic analysis.
  • Cerber’s network traffic and code are encrypted, making it harder to intercept or analyze. Macroses in phishing attachments often include junk code to confuse detection tools.
  • For persistence, Cerber may establish itself in the system registry or running processes to ensure it reactivates after reboots.

Execution process of Cerber Ransomware

Let's use ANY.RUN's Interactive Sandbox to analyze a sample of the Cerber Ransomware to see how it operates.

Cerber ransomware uses a multi-stage execution chain, often starting with distribution via phishing emails. These emails typically include malicious attachments—either zipped Windows Script Files (WSF) or Microsoft Office files (.DOC or .DOCX). The WSF file directly installs Cerber, while the Office documents prompt users to enable macros, which then download and install the malware. Cerber has also been observed exploiting known vulnerabilities to gain initial access.

View sandbox analysis

Cerber ransomware analysis in ANY.RUN Process analysis of Cerber ransomware in ANY.RUN's Interactive Sandbox

Once executed, Cerber may check for specific mutexes to avoid reinfecting the same machine. In this case, the mutex is SHELL.{9C578142-9AC8-5286-EEAE-C741EB3192B8}, and the ransomware also created several additional mutexes. It checks the system’s country location and terminates if it detects an ex-USSR region. To evade detection, Cerber can configure Windows Firewall rules to block outbound traffic from security tools. Some versions add a time delay to the attack chain to evade sandbox analysis.

Cerber often reboots the system into Safe Mode with Networking, then back to normal mode before initiating the encryption process. It uses AES-256 and RSA to encrypt files, appends a custom extension, and renames files with randomly generated strings. In this analysis, the extension used was “.ae90.” Cerber stores ransom instructions locally, can change the desktop wallpaper, and launches a ransom note in HTA format using mshta.exe. Finally, it deletes its own file from the infected system to conceal its presence.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Gathering threat intelligence on Cerber malware

Countering Cerber demands proactive threat hunting and protective measures. Leverage threat intelligence to track Cerber-related indicators of compromise like C2 domains & IPs, hashes of known Cerber variants, Tor-based payment portals used by attackers (e.g., port 6893 with specific packet structures like Machine GUID hashes).

Cerber ransomware results in ANY.RUN TI Lookup TI Lookup helps users collect fresh intel on Cerber Ransomware attacks

Threat Intelligence Lookup by ANY.RUN delivers fresh contextual data on IOCs and provides a selection of the malware’s samples in action detonated in the Interactive Sandbox. Learn more about TI Lookup.

TI Lookup search by a port typically engaged by Cerber gives a number of IOCs for further research: associated URLs, files, mutexes, etc.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Distribution methods of Cerber Ransomware

  • The main method is phishing emails with malicious attachments. Fake invoices, job offers, or security alerts trick victims into downloading malicious Word or Excel files containing macros that drop Cerber.
  • Also used: malvertising and drive-by downloads, compromised websites and exploit kits targeting browser and software vulnerabilities.
  • Cerber is distributed via TrickBot and Dridex—malware families that serve as initial access brokers for ransomware operators.
  • Adversaries can brute-force RDP credentials to gain remote access, disable security tools, and manually deploy Cerber inside corporate networks.
  • Cerber as an RaaS is distributed by various cybercriminals who customize campaigns, making its delivery methods and sender addresses highly variable.
  • Cerber can spread laterally across a network, infecting shared drives and removable media.

Conclusion

Cerber stands out as a highly adaptive ransomware threat, blending traditional infection vectors with cutting-edge evasion techniques. Its danger lies in its ability to target both individuals and organizations, steal data, and disrupt operations while evading detection. By combining robust endpoint security, network monitoring, and real-time threat intelligence, defenders can detect and neutralize Cerber effectively.

Sign up for a free ANY.RUN account to access malware analysis and threat intelligence tools for your company

HAVE A LOOK AT

PureCrypter screenshot
PureCrypter
purecrypter
First identified in March 2021, PureCrypter is a .NET-based loader that employs obfuscation techniques, such as SmartAssembly, to evade detection. It has been used to distribute malware families including AgentTesla, RedLine Stealer, and SnakeKeylogger. The malware is typically delivered through phishing campaigns and malicious downloads, often masquerading as legitimate files with extensions like .mp4 or .pdf. PureCrypter utilizes encryption and compression to conceal its payloads and can inject malicious code into legitimate processes to maintain persistence on the infected system.
Read More
Kamasers screenshot
Kamasers
kamasers
Kamasers is a multi-functional DDoS botnet malware that transforms infected machines into remotely controlled attack nodes. It combines network-layer flooding capabilities, resilient command-and-control (C2), and payload delivery, making it not just a disruption tool but a gateway to broader compromise.
Read More
Qilin Ransomware screenshot
Qilin ransomware (predecessor known as “Agenda”) is a rapidly evolving ransomware-as-a-service (RaaS) operation targeting organizations worldwide. Known for double extortion tactics (encrypting files while also threatening to leak stolen data) Qilin has quickly gained notoriety for its customization, flexibility, and impact on critical infrastructure.
Read More
Trojan screenshot
Trojan
trojan trojan horse
Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.
Read More
BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More
Stealer screenshot
Stealer
stealer
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Read More