Cerber Ransomware: How It Works, History, and Removal

Cerber ransomware pioneered the RaaS model in 2016 and returned in 2024 as a Linux payload. Explore how it works, its versions, and how to remove it.
Published on
Tuesday, October 6, 2026
Updated on
October 6, 2026

Cerber ransomware is file-encrypting malware that pioneered the ransomware-as-a-service model in 2016, renting itself to affiliates who kept the larger share of every ransom they collected. One name now covers two distinct threats separated by eight years.

First came a 2016 Windows wave that Microsoft tracked across two delivery channels, malicious spam attachments and the RIG exploit kit, with later versions built to encrypt 493 distinct file types. Second came a 2024 Linux variant striking enterprise Confluence servers, a target unlike anything in the original consumer wave.

Cerber Ransomware Key Facts

Cerber ransomware carries a consistent identity across its versions, encrypting files, appending a distinctive extension, and demanding Bitcoin through a ransom note that reads itself aloud.

Attribute Detail
Malware type File-encrypting ransomware, offered as ransomware-as-a-service
First observed February 2016, advertised on a criminal forum
Affected platforms Windows from 2016; Linux through a 2024 variant
Encryption RSA with RC4 in early builds; AES-256 with RSA-2048 in later ones
File extensions .cerber, a random four-character string, or .L0CK3D on Linux
Ransom note #DECRYPT MY FILES# text plus a spoken audio message
Primary delivery Phishing attachments, exploit kits, later direct CVE exploitation
Current status Largely dormant since 2018; Linux resurgence in 2024

How Cerber Ransomware Works

Cerber ransomware works in three phases: it reaches a system through a delivery channel, encrypts files with a layered cipher, and hides its code from analysis. Each phase evolved across the malware's lifespan.

Phase 1. Initial Access and Delivery

Phishing carried Cerber in its earliest campaigns. Malicious Word documents attached to spam email ran VBScript macros on the victim's confirmation, downloading the payload through a trojan loader that Microsoft tracked as Donoff.

Exploit kits opened a second, click-free path. RIG, Magnitude, and Neutrino kits scanned visitors to compromised websites for outdated Flash, Silverlight, and browser versions, then exploited flaws such as CVE-2015-8651 to install Cerber with no user action. Later intrusions used offensive frameworks including Cobalt Strike and Sliver.

Phase 2. Encryption Mechanism

Cerber uses a hybrid cipher, encrypting file contents with a symmetric algorithm and locking that key with asymmetric RSA so only the attacker's private key reverses it. Early builds paired RSA with the RC4 stream cipher, and later variants moved to AES-256 for file encryption, generating a unique key per infection.

Extension behavior shifted across versions. Initial releases appended .cerber, and subsequent builds switched to a random four-character extension unique to each victim, which complicated signature-based recovery.

Phase 3. Evasion and Anti-Analysis

Cerber payloads ship packed with UPX, which stores the real code encoded inside the binary and unpacks it into memory at runtime to defeat static scanning. Heavily obfuscated C++ resists reverse engineering across every payload.

Geographic and environment checks guard execution. Early Cerber terminated if it detected a system in several former Soviet states, and separate routines probed for the sandbox conditions that malware analysts rely on.

Cerber Ransomware-as-a-Service Model

Cerber's business model drove its scale more than any technical feature. A developer advertised the malware on a criminal forum in February 2016 and recruited affiliates who kept 60% of each ransom while the developer took the remaining 40%.

Volume followed from that division of labor. Affiliates ran many concurrent distribution campaigns while the developer focused on the malware, shipping updates almost weekly to stay ahead of decryptors and detection tooling.

The affiliate model itself was the innovation. Recruitment, payment splitting, and campaign infrastructure all ran through darknet channels, and continuous dark web monitoring of those forums is how researchers first mapped Cerber's scale and later its decline.

Cerber Ransomware Version History

Cerber moved through six major versions between 2016 and 2017, each adjusting extensions, delivery, or evasion. Version changes tracked the developer's response to decryption tools and detection.

Version Period Notable changes
v1 March 2016 Initial release; .cerber extension; audio ransom note; RSA and RC4 encryption
v2 Mid 2016 Patched the flaw behind an early free decryptor; hardened key handling
v3 Late summer 2016 Refined distribution through Magnitude and Neutrino exploit kits
v4 October 2016 Random four-character extension replacing .cerber; 493 file types targeted
v5 Late 2016 Faster encryption; red ransom wallpaper replacing the earlier green
v6 Early 2017 RIG-V VIP exploit kit; Blank Slate spam; CVE-2017-0199 exploitation

2024 Linux Resurgence Against Confluence Servers

After years of near-total dormancy, Cerber resurfaced in 2024 against Linux servers. Researchers at Cado Security, now part of Darktrace, documented a Cerber variant deployed onto Atlassian Confluence servers, a target profile with no resemblance to the 2016 consumer campaigns.

how cerber struck confluence

Exploiting CVE-2023-22518 in Confluence

Access began with an improper-authorization vulnerability in Confluence Data Center and Server, tracked as CVE-2023-22518. Atlassian escalated the flaw to CVSS 10.0, the highest rating on the scale, after observing ransomware exploitation in the wild.

The vulnerability let an attacker reset the application and create a new administrator account through an unprotected configuration-restore endpoint. That account then uploaded the Effluence web shell, which runs arbitrary commands on the host.

Three-Payload Encryption Chain

Cerber's Linux variant runs as three UPX-packed C++ payloads. A primary stager writes a lock file, pulls a secondary payload from a command-and-control server, and deletes itself from disk while continuing in memory.

The second payload, a log checker, tests write access to a target directory, likely a permission or sandbox check. The third payload, the encryptor, walks the root filesystem, drops a ransom note in each writable directory, overwrites file contents with their encrypted form, and appends a .L0CK3D extension.

how cerber struck confluence

Why the Linux Impact Stays Limited

Privilege bounds the damage. Confluence typically runs as a low-privilege user, so the encryptor reaches only files that the user owns rather than the whole system. Well-configured servers keep backups of the Confluence datastore, which further reduces the leverage the encryption provides, and the ransom note's claim of data theft went unsupported by observed behavior.

Cerber Attack Timeline and Decline

Cerber's activity traces a clear arc across three phases.

  • 2016 peak: Cerber ranked among the year's highest-volume ransomware families, spread through spam and exploit kits, targeting individuals and businesses with little sector discrimination.
  • 2017 evolution: Weekly updates, new exploit kits, and fresh spam campaigns such as Blank Slate sustained activity, while free decryptors for older versions eroded affiliate returns.
  • 2018 decline: Affiliates migrated to newer families including GandCrab and SamSam, and reported Cerber activity fell to near zero.
  • 2024 resurgence: A Linux variant exploiting Confluence servers revived the name against enterprise targets, distinct in platform and method from the original.

How to Detect Cerber Ransomware

Detecting Cerber ransomware combines file-system artifacts with behavioral signals, since packing defeats simple signature scanning.

  • Encrypted-file extensions: Files renamed with .cerber, a random four-character extension, or .L0CK3D on Linux indicate active or completed encryption.
  • Ransom-note artifacts: Notes titled #DECRYPT MY FILES# or read-me3.txt dropped across directories, alongside the audio message on Windows variants.
  • Packing and Yara matches: UPX-packed payloads match existing UPX Yara rules, a starting point for hunting the C++ binaries.
  • Behavioral encryption signals: Rapid sequential file reads and rewrites, mass renames, and log markers such as the Linux variant's log.0 and log.1 files flag encryption in progress.

MITRE ATT&CK Techniques Used by Cerber

Cerber's behavior maps to several MITRE ATT&CK techniques, which lets detection engineers align rules to each stage of an infection.

Tactic Technique (ID) Cerber behavior
Initial Access Exploit Public-Facing Application (T1190) RIG exploit kit in 2016; CVE-2023-22518 in Confluence in 2024
Initial Access Phishing (T1566) Malicious Office attachments running VBScript macros
Defense Evasion Obfuscated or Packed Files (T1027) UPX-packed, heavily obfuscated C++ payloads
Defense Evasion Virtualization and Sandbox Evasion (T1497) Environment and sandbox checks before execution
Impact Data Encrypted for Impact (T1486) File encryption followed by a Bitcoin ransom demand

How to Remove Cerber Ransomware and Recover Files

To remove Cerber ransomware and recover files, work through six steps, and set expectations honestly on the limits of decryption.

  1. First, isolate the infected system. Disconnect it from the network and shared drives to stop encryption spreading to reachable files and backups.
  2. Second, identify the variant. The extension and ransom-note name point to the version, which determines whether any free decryptor applies.
  3. Third, preserve evidence and report. Capture ransom notes, sample encrypted files, and logs, then report to national channels such as the FBI IC3 or a local cybercrime authority.
  4. Fourth, remove the malware. A reputable endpoint tool removes active Cerber payloads, cleaning the infection without decrypting the already-locked files.
  5. Fifth, restore from backup where possible. Offline or immutable backups are the reliable recovery path. Free decryptors released for early Cerber versions in 2016 no longer help against later builds, which remain uncrackable.
  6. Sixth, harden before reconnecting. Patch the entry point, rotate credentials, and confirm monitoring before returning the system to production, since reinfection through the same gap is common.

How to Prevent Cerber and Similar Ransomware

Preventing Cerber and similar ransomware means closing the entry paths every version relied on. Broader ransomware prevention guidance extends these controls, and documented ransomware attack examples show the same gaps recurring across families.

  • Patch internet-facing applications: The 2024 Confluence campaigns exploited a known, patchable flaw, so timely patching of exposed services closes the modern Cerber vector.
  • Control Office macros: Blocking macros in documents from email removes the VBScript path that carried early Cerber.
  • Filter email and enforce authentication: Attachment scanning and sender authentication cut the phishing volume that delivered the original campaigns.
  • Apply least privilege: Running services as low-privilege users limits how many files any encryptor reaches, as the Confluence cases showed.
  • Maintain offline backups: Immutable, offline backups are the single control that defeats encryption-based extortion outright.

FAQs About Cerber Ransomware

Is Cerber ransomware still active?

Cerber ransomware is still mostly inactive in its original form, having declined to near zero by 2018, though a Linux variant revived the Cerber name against Confluence servers in 2024.

Can Cerber-encrypted files be decrypted?

No, most Cerber-encrypted files cannot be decrypted. Free tools cracked early 2016 versions, but later builds use secure encryption with no known decryptor, leaving backups as the recovery path.

What file extension does Cerber ransomware add?

Cerber ransomware adds the .cerber file extension in early versions, a random four-character extension in later Windows builds, and a .L0CK3D extension in the 2024 Linux variant.

Does Cerber ransomware steal data or only encrypt it?

Cerber ransomware primarily encrypts data rather than stealing it. Its 2024 Linux ransom note claimed exfiltration, but researchers observed no data-theft behavior supporting that claim.

What made Cerber ransomware different from other ransomware?

What made Cerber ransomware different was its early ransomware-as-a-service model and its audio ransom note, which read the demand aloud and earned it the name the ransomware that speaks.

Does Cerber ransomware affect Linux?

Yes, Cerber ransomware does affect Linux through a 2024 variant. This Cerber ransomware variant affects Linux Confluence servers via CVE-2023-22518, encrypting files owned by the low-privilege Confluence user.

Related Posts
9 Common Ransomware Attack Vectors in 2026
Ransomware attacks in 2026 can begin through vulnerability exploitation, compromised credentials, brute force, phishing, malware, third-party access, and brokered access.
10 Automotive Cybersecurity Threats Reshaping the Industry in 2026
Automotive cybersecurity in 2026 covers ransomware, supplier compromise, OTA risks, vehicle networks, AI threats, regulations, and attack-path prioritization across OEMs.
7 Best Supply Chain Risk Management Platforms in 2026
Seven supply chain risk management platforms for 2026, covering cyber exposure, supplier screening, risk assessments, analytics, workflows, procurement, and governance.

Start your demo now!

Schedule a Demo
Free 7-day trial
No Commitments
100% value guaranteed

Related Knowledge Base Articles

No items found.