{"id":1972,"date":"2017-01-06T01:08:00","date_gmt":"2017-01-06T00:08:00","guid":{"rendered":"http:\/\/borncity.com\/win\/?p=1972"},"modified":"2021-06-10T09:39:14","modified_gmt":"2021-06-10T07:39:14","slug":"no-end-for-cerber-ransomware","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2017\/01\/06\/no-end-for-cerber-ransomware\/","title":{"rendered":"No end for Cerber Ransomware in 2017"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" align=\"left\" height=\"47\">Cerber Ransomware has been on the raise in 2016. There has been several campaigns \u2013 and the worse thing: it seems that Cerber won't fade away in 2017.<\/p>\n<p><!--more--><\/p>\n<p>A fake credit card email campaigns addressed people who are shopping lately for holiday season 2016 contains a Cerber download link (see <a href=\"https:\/\/blogs.technet.microsoft.com\/mmpc\/2016\/12\/13\/been-shopping-lately-fake-credit-card-email-can-spook-you-into-downloading-cerber-ransomware\/\" target=\"_blank\" rel=\"noopener\">this Microsoft article<\/a>). But there has been several campaigns over the last months of 2016 (see the graph below).<\/p>\n<p>&nbsp;<img loading=\"lazy\" decoding=\"async\" title=\"Cerber campaigns\" alt=\"Cerber campaigns\" src=\"https:\/\/web.archive.org\/web\/20170207124535\/https:\/\/msdnshared.blob.core.windows.net\/media\/2016\/12\/cerber-machine-encounters.png\" width=\"628\" height=\"359\"><br \/>(Source: Microsoft)<\/p>\n<p>Cerber will be distributed in most cases via an e-mail attachment, like it is shown below as a zip attachment.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"Cerber attachment\" alt=\"Cerber attachment\" src=\"https:\/\/web.archive.org\/web\/20170207100438\/https:\/\/msdnshared.blob.core.windows.net\/media\/2016\/12\/cerber-email-1.png\" width=\"624\" height=\"417\"><br \/>(Source: Microsoft)<\/p>\n<p>Microsoft has analyzed telemetry data from Windows Defender. The result shows that this latest exploit kit attack that leads to Cerber largely affects Asia and Europe.<\/p>\n<p><img decoding=\"async\" title=\"Cerber infections\" alt=\"Cerber infections\" src=\"https:\/\/web.archive.org\/web\/20170207105655\/https:\/\/msdnshared.blob.core.windows.net\/media\/2016\/12\/cerber-rig-exploit-distribution.png\"><br \/>(Source: Microsoft)<\/p>\n<p>Each campaign delivers variants of Cerber, but all variants tries to encrypt user data on infected systems and ask for money to unencrypt the data. Windows 10 has security technologies that can detect this new batch of updated Cerber ransomware. Microsoft is discussing further details about Cerber within <a href=\"https:\/\/blogs.technet.microsoft.com\/mmpc\/2016\/12\/21\/no-slowdown-in-cerber-ransomware-activity-as-2016-draws-to-a-close\/\" target=\"_blank\" rel=\"noopener\">this Technet blog post<\/a>. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cerber Ransomware has been on the raise in 2016. There has been several campaigns \u2013 and the worse thing: it seems that Cerber won't fade away in 2017.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580,2],"tags":[615,243,69,194],"class_list":["post-1972","post","type-post","status-publish","format-standard","hentry","category-security","category-windows","tag-cerber","tag-ransomware","tag-security","tag-windows"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/1972","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=1972"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/1972\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=1972"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=1972"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=1972"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}