Actor Profile

🏹 bert — Ransomware

BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across healthcare, technology, and event services sectors in Asia, Europe, and the US, with ransomware derived from a Linux variant of REvil using AES encryption and multi-threaded file locking.
🔄 Pivot:🌎 US🏹 bert

Classification

Ransomware

Leak-site victims

7
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (7)

VictimCountryPublishedDomain
S5 Agency World GB 2025-06-10T05:44:36.366203+00:00 s5agencyworld.com
Columbia TI CO 2025-06-05T14:22:45.423640+00:00 columbiati.com.br
Wawasan Dengkil Sdn Bhd MY 2025-05-22T07:42:32.077668+00:00 wawasandengkil.com.my
ALL RING TECH CO., LTD. TW 2025-05-16T14:16:54.439914+00:00 allringtech.com
SIMCO Electronics US 2025-04-30T19:24:13.076196+00:00 simco.com
Yozgat City Hospital TR 2025-04-09T07:19:10.756580+00:00 yozgatsehir.saglik.gov.tr
National Ticket Company US 2025-04-06T10:41:13.423760+00:00 nationalticket.com

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

📁 Case Management

+ New case from this

🏹 Add to case

Attach bert (Actor / APT) and pull all linked entities:

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php