Malware News New Cerber Ransomware Variant Released That Keeps Original Filename

Solarquest

Moderator
Thread author
Verified
Staff Member
Malware Hunter
Well-known
Jul 22, 2014
2,525
Since the Cerber Ransomware was first released back in early March of 2016, this ransomware would not only encrypt your files, but would also annoyingly encrypt the file names as well. This made it difficult for users and administrators to determine what files were actually encrypted and restore them from backups.

While many variants of Cerber have been released over time, this "feature" has always remained the same. That is until today, when both Emsisoft researcher Sarah, otherwise known as xXToffeeXx, and SwiftOnSecurity found a new sample of Cerber that leaves the original filename the same and only appends a random extension as shown below.

more in the link above...
 

vemn

Level 6
Verified
Malware Hunter
Well-known
Feb 11, 2017
264
YeH... already seen it in action... users not aware when they got infected as the files looks just fine till users opened them.

Innovation at its best.
They also do QC on their "products".... zzz
 
  • Like
Reactions: Der.Reisende

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top