The Cerber ransomware is no more. The ransomware itself is still active, but now goes by a different name. As of last week, the malicious tool has rebranded to CRBR. Developers may be trying to confuse security researchers countering its efforts. It is not a new cyber threat, so current protection and countermeasures should hold up to it.
Even ransomware developers have to properly evaluate their business model. As we so often see in the technology sector, a rebranding can revitalize a business. Cerber has never suffered from a lack of popularity. However, the developers felt now is a good time to rebrand to CRBR Encryptor. The new cover does not mean this malware threat is more potent than before, since it is literally the same programming.
The main thing to remember is how Cerber will always remain Cerber, regardless of what it is officially called by its developers. This rebranding effort does not introduce any new changes under the hood. We have seen multiple malware threats this year so far, and a more potent Cerber is not on anyone’s wish list right now.
It appears the rebranded Cerber is actively distributed through a few dedicated campaigns currently. The MagnitudeEK exploit kit seems to be the main source of distribution for the time being. Malicious individuals can install CRBR ENCRYPTOR by taking advantage of an exploit to attack vulnerable systems. A new spam email campaign is making the rounds, which is distributing the malware in the form of an email attachment.
Researchers believe other methods of distribution may also be in effect, although they have yet to be analyzed fully. We know it is the same Cerber as before when we look at how it encrypts files. This is both good and bad news, as system administrators still detest Cerber. The most annoying part is how CRBR ENCRYPTOR will still scramble file names. It is far from the worst part of this ransomware, but still annoying.
On the payment front, very little has changed. Victims are redirected to a Tor-based website where they need to make a 0.5 BTC payment. Failing to do so will increase the price to 1 Bitcoin after five days. This is just a repackaged version of one of the most annoying ransomware types in history. The bigger question is what the developers hope to achieve by switching the name to CRBR ENCRYPTOR, as it offers no obvious advantages.
Contrary to what most people would have expected, this is not a different type of malware, nor it is a copy-paste project. It is the official Cerber ransomware as we have seen so many times. This is a very strange decision by the ransomware developers, as there appears to be no good reason to have done it. Even the new name is not all that different from Cerber.
Livestream tokens on Pump.fun are rewriting the playbook for creator monetization. They’ve opened a floodgate…
FTX is set to make another round of creditor payouts. Yesterday, the exchange confirmed it…
The stablecoin market just got a major shake-up. Reeve Collins, the cofounder of Tether, the…
Justin Sun, CEO of TRON DAO, has just made one of his biggest announcements of…
$BNB has broken through a historic milestone. The token surged past $1,000, setting a new…
Decentralized finance (DeFi) has continued to disrupt traditional financial systems, offering permissionless access to lending,…