BERT is a new ransomware group known for multi-threaded encryption tactics derived from a Linux variant of REvil.
Analyst brief
BERT is a newly emerged ransomware group operating with criminal intent. It targets healthcare, technology, and event services sectors across Asia, Europe, and the US. The group uses ransomware derived from a Linux variant of REvil, employing AES encryption and multi-threaded file locking techniques on both Windows and Linux platforms. Defenders should focus on detecting multi-threaded encryption behavior and Linux-based ransomware tactics targeting these sectors.
bert
crime
BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across healthcare, technology, and event services sectors in Asia, Europe, and the US, with ransomware derived from a Linux variant of REvil using AES encryption and multi-threaded file locking.