BERT Ransomware Threatens ESXi Virtual Machine

Search for a command to run...

No comments yet. Be the first to comment.
Tổng Quan Hãy tưởng tượng: một nhân viên nhân sự tại một công ty hàng không ở Pakistan nhận được lời mời phỏng vấn hấp dẫn từ một thương hiệu tuyển dụng có vẻ rất quen thuộc. Một cuộc gọi video được l

Tóm tắt Ngày 19/03/2026, cơ quan chức năng Mỹ, Canada và Đức triệt phá hạ tầng của bốn botnet IoT lớn nhất từng được ghi nhận — Aisuru, Kimwolf, JackSkid và Mossad. Hơn ba triệu thiết bị bị nhiễm. Hơn

Tóm tắt Không có malware nào trong chiến dịch này. Payload cuối cùng mà nạn nhân nhận được là trình cài đặt chính thức của Level RMM, tải trực tiếp từ hạ tầng của chính Level, cài đặt bằng msiexec với

Phần lớn dữ liệu thu được từ một honeypot SSH internet-facing là nhiễu: dò mật khẩu liên tục, hoặc bot đăng nhập thành công rồi tải payload xuống chạy ngay lập tức. Nhưng ngày 27/6/2026, honeypot của

Từ tháng 1/2025, một nhóm tấn công chưa xác định danh tính đã duy trì hoạt động gián điệp mạng nhắm vào các cơ quan chính phủ tại Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan và Syria,

BERT Ransomware, a new type of ransomware, has recently been identified as the main cause of attacks targeting virtualization technology like ESXi in businesses, causing significant damage to organizations and severely hindering system recovery efforts.
BERT Ransomware - also known as "Water Pombero," is a hacker group that emerged in April 2025, primarily targeting virtualization systems, databases, and storage servers of organizations in the healthcare, technology, and events sectors across Asia, Europe, and the Americas.
In the latest security report, this ransomware has been enhanced and has become more dangerous due to new mechanisms in the Linux version. Specifically, this ransomware has developed the ability to detect and force Linux virtual machines in ESXi to shut down before encrypting all data within the affected virtual machines. This ensures that the targeted virtual machines cannot operate during the attack, thereby preventing any incident response efforts from administrators.

Figure 1: Malware executing commands to force virtual machines in the system to stop operating - Source: CyberSecurityNews
In addition to its ability to attack multiple platforms on Windows, Linux, and ESXi systems, BERT ransomware can support up to 50 simultaneous encryption threads, enhancing its processing capability in large-scale virtualization environments.
For Windows systems, BERT uses PowerShell scripts as loaders to disable default security features like Windows Defender, firewall, UAC, etc., before downloading the main payload from the C2 server.

Figure 2: Malware PowerShell script disabling default security features on Windows - Source: CyberSecurityNews
Advanced PowerShell Monitoring: Monitor scripts running on PowerShell to detect loaders that disable security tools like firewalls, Windows Defender, and UAC early.
Network Segmentation: Isolate the ESXi management interface from the rest of the system to reduce the risk of spreading when a server is compromised.
Strengthen Virtualization Infrastructure Defense: Enhance security solutions for platforms like VMware ESXi and virtual servers.
Data Backup: Use measures like offline backups or immutable backups to protect against ransomware encrypting or deleting data.