Malware News Cerber Ransomware switches to .CERBER3 Extension for Encrypted Files

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
VIDEO: Video Review - Cerber3 Ransomware - Demonstration of attack by @CyberSecurity GrujaRS
-----------------------------------------------------
A new version of the Cerber Ransomware has been discovered by AVG security researcher Jakub Kroustek that switches from the .CERBER2 extension to .CERBER3 for encrypted files. When I tested this new sample, there was some minor outward differences between this version and the previous version.

The most notable difference is that this new version will now append the .CERBER3 extension to encrypted files. This is shown in the sample pictures folder shown below.

encrypted-files.jpg


Another notable difference is that this version has changed the ransom note names to # HELP DECRYPT #.html, # HELP DECRYPT #.txt, and # HELP DECRYPT #.url.

This version of Cerber continues to use the 31.184.234.0/23 range of IP addresses for stats purposes.

Read more: Cerber Ransomware switches to .CERBER3 Extension for Encrypted Files
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top