Cerber Ransomware-as-a-Service
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
Nemacod is a JavaScript malware download document. Cerber targets all popular file types including images, videos, documents and more.
The recent campaign uses phishing emails containing malicious attachments in the form of a .zip file. The attachment purports to be PDF titled “DOC<10 random digits>-PDF.js”
One particular variant of the new Cerber ensures it does not encrypt files relating to security products including firewall, anti-virus and anti-spyware products. This is believed to be the author showcasing their ability to target security product vendors’ user base and encrypt all files right in front of them. This functionality is present in only one variant which suggests that it was modified by the user renting it.
Cerber is sold on dark web black markets as a service, offering customisation on the part of those who use it. It remains a popular choice for cyber criminals as there is no free decryption service available for it.
In this campaign, the attackers are demanding 1BitCoin (BTC) for decryption.
Remediation steps
Last edited: 17 February 2020 11:27 am