BERT Ransomware Quietly Gains Global Ground

Amber | Attack Report
Download PDF

BERT ransomware, active since March 2025, has rapidly evolved into a multi-platform threat targeting systems across critical sectors. Leveraging REvil’s code and demanding Bitcoin via the Session messenger, the campaign’s growing operational footprint and double-extortion tactics signal a persistent and escalating threat landscape for global enterprises.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox