Cerber

Category: ransomware · Aliases: None known · Sample count (EMBER 2018): 1,792 · Enrichment: hand-curated · Updated: 2026-05-27

Overview

Cerber is a ransomware-as-a-service family active from 2016 to 2018 that became one of the most prevalent ransomware strains during that period, distributed through exploit kits, malspam, and the RIG and Magnitude EKs. It uses RSA-2048 plus RC4 encryption and is notable for its audio ransom note that reads the demand aloud. Cerber operators rapidly iterated through multiple versions to evade detection and decryption tools.

MITRE ATT&CK Techniques

This family has been observed using the following ATT&CK techniques: T1486 T1490 T1083

Frequently Asked Questions

What is Cerber?

Cerber is a ransomware-as-a-service family active from 2016 to 2018 that became one of the most prevalent ransomware strains during that period, distributed through exploit kits, malspam, and the RIG and Magnitude EKs. It uses RSA-2048 plus RC4 encryption and is notable for its audio ransom note that reads the demand aloud. Cerber operators rapidly iterated through multiple versions to evade detection and decryption tools.

How does Cerber spread?

Cerber spreads through exploit kits like RIG and Magnitude, malicious email attachments, and as a secondary payload from other loaders.

What are the signs of a Cerber infection?

Files renamed with .cerber, .cerber2, or .cerber3 extensions, ransom notes named _README_.hta, and a synthesized voice ransom message are signature indicators.

What should I do if I think I have Cerber on my system?

If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Need help with an active incident? If you suspect this malware on your system, do not attempt manual removal. Contact SystemHelpdesk expert MSP support at 855-783-7555 for professional incident response guidance.

Machine-readable

Get this profile as JSON: https://jordanricky1604-ship-it.github.io/malware-families-catalog/api/cerber.json

About this catalog

This profile is part of the Malware Families Catalog, a public dataset of 2,899 malware families extracted from the EMBER 2018 benchmark. The catalog is also published on Hugging Face and Kaggle.