🏹 bert — Ransomware
BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across healthcare, technology, and event services sectors in Asia, Europe, and the US, with ransomware derived from a Linux variant of REvil using AES encryption and multi-threaded file locking.
Classification
Ransomware
Leak-site victims
7
Ransomware.live
Associated IoCs
0
local intel
MITRE techniques
—
ATT&CK
Tracked
Yes
Ransomware.live
🔥 Leak-Site Victims (7)
| Victim | Country | Published | Domain |
|---|---|---|---|
| S5 Agency World | GB | 2025-06-10T05:44:36.366203+00:00 | s5agencyworld.com |
| Columbia TI | CO | 2025-06-05T14:22:45.423640+00:00 | columbiati.com.br |
| Wawasan Dengkil Sdn Bhd | MY | 2025-05-22T07:42:32.077668+00:00 | wawasandengkil.com.my |
| ALL RING TECH CO., LTD. | TW | 2025-05-16T14:16:54.439914+00:00 | allringtech.com |
| SIMCO Electronics | US | 2025-04-30T19:24:13.076196+00:00 | simco.com |
| Yozgat City Hospital | TR | 2025-04-09T07:19:10.756580+00:00 | yozgatsehir.saglik.gov.tr |
| National Ticket Company | US | 2025-04-06T10:41:13.423760+00:00 | nationalticket.com |
Source: Ransomware.live leak-site monitoring (cached, offline-safe).
📁 Case Management
🏹 Campaigns & malware
🏹 Add to case
🧩 Advanced Capabilities
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron