Updated Red Cerber 2017
A new variant of Cerber ransomware named “Updated Red Cerber 2017” is being distributed by spam email campaigns.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A new variant of Cerber ransomware named “Updated Red Cerber 2017” is being distributed by spam email campaigns.
Affected platforms
The following platforms are known to be affected:
Threat details
It is offered as Ransomware as a Service (RaaS). RaaS enables unskilled attackers to buy and launch their own ransomware campaigns from the TOR network.
The spam e-mails contain a malicious attachment which consists of a macro enabled word document within two levels of zipped archive folders. The technique of archiving within an archive is called “doublezipping” and is used in an attempt to hide the payload from detection by AV software.
Remediation steps
Last edited: 17 February 2020 11:40 am