Ransomware group profile · #224 by claimed victims
Bert ransomware
BERT is a newly emerged ransomware group first identified in mid-2025, targeting Windows and Linux platforms across healthcare, technology, and event services sectors in Asia, Europe, and the US, with ransomware derived from a Linux variant of REvil using AES encryption and multi-threaded file locking.
Victimology
Who Bert claims to have breached, from 7 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 7 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| S5 Agency World s5agencyworld.com | Transportation | GB | 10 Jun 2025 |
| Columbia TI columbiati.com.br | Technology | CO | 5 Jun 2025 |
| Wawasan Dengkil Sdn Bhd wawasandengkil.com.my | Other | MY | 22 May 2025 |
| ALL RING TECH CO., LTD. allringtech.com | Technology | TW | 16 May 2025 |
| SIMCO Electronics simco.com | Technology | US | 30 Apr 2025 |
| Yozgat City Hospital yozgatsehir.saglik.gov.tr | Healthcare | TR | 9 Apr 2025 |
| National Ticket Company nationalticket.com | Professional Services | US | 6 Apr 2025 |
All 7 Bert victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Bert is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Bert ransomware still active?
How many victims has Bert claimed?
Which industries does Bert target?
Which countries are most affected by Bert?
Where does VULONE get Bert victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].