Intel Name: Bert ransomware group targets asia and europe on multiple platforms
Date of Scan: July 8, 2025
Impact: High
Summary: BERT (also known as Water Pombero) is a recently identified ransomware group targeting both Windows and Linux systems, with confirmed attacks in Asia, Europe, and the US. Their victims span healthcare, technology, and event services sectors. BERT employs PowerShell loaders, privilege escalation, and simultaneous file encryption to execute efficient and evasive attacks. On Linux, their ransomware supports up to 50 threads for rapid encryption and can forcibly shut down ESXi VMs to hinder recovery.