Ransomware Group intelligence
Bert
InactiveTrack Bert with 9 published victims and 2 known leak locations in a single intelligence view.
Overview
Bert is tracked by Breach House as a ransomware group with 9 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 58m ago | hptqq2o2qjva7lcaaq67w36jihzivkaitkexorauw7b2yul2z6zozpqd.onion |
| Leak location 1 | Onion service | Down checked 57m ago | bertblogsoqmm4ow7nqyh5ik7etsmefdbf25stauecytvwy7tkgizhad.onion |
Top Activity Sectors (5)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Bert, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: bert uses PowerShell scripts to execute malicious commands and spread payloads across compromised systems.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: bert adds malicious registry run keys to ensure persistence across reboots on infected hosts.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: bert disables antivirus and monitoring tools by terminating security processes and modifying system configurations.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: bert encodes victim files with symmetric encryption keys before demanding payment for decryption.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: bert deletes Volume Shadow Copies and backup files via command-line utilities to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: bert discovers remote systems via port scanning to expand foothold within the network.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1049 System Network Connections Discovery Discovery
What they do: bert enumerates active network connections to identify high-value targets for lateral movement.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: bert probes network shares using SMB tools to identify additional victims for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: bert encrypts victim files using custom ransomware binaries targeting critical data directories.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1491.001 Internal Defacement Impact
What they do: bert displays ransom notes and defaces web content on compromised servers to pressure victims.
What that means: An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
note.txt
Hello from Bert! Your network is hacked and files are encrypted. We download some important files from your network. Instructions for contacting our team: Download the (Session) messenger (https://getsession.org) in messenger :ID 05149ef8a65c342bc76bad335ad3a314ec1321b18cdb6092667083b4e56a4dcb41 bertblogsoqmm4ow7nqyh5ik7etsmefdbf25stauecytvwy7tkgizhad.onion our blog
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (9)
Search, filter and paginate the victim timeline for Bert. Showing 1–9 of 9.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | S5 Agency World id20547 View details | United Kingdom | Communication / Marketing | ||
|
S5 Agency World is a global port agency operating in over 360 ports, specializing in vessel and cargo services. |
|||||
| Ransomware | Columbia TI id20460 View details | Colombia | IT | ||
|
Columbia Integração delivers IT solutions in cloud, cybersecurity, and infrastructure to drive digital transformation for businesses in Brazil. |
|||||
| Ransomware | Wawasan Dengkil Sdn Bhd id20187 View details | Malaysia | Construction / Real Estate | ||
|
Wawasan Dengkil Sdn Bhd is a Malaysian construction company founded in 2003. It specializes in earthworks, civil engineering, equipment rental, and building material supply. Recently listed on the stock exchange, the company is actively expanding its operations. |
|||||
| Ransomware | ALL RING TECH CO., LTD. id20083 View details | Taiwan, Province of China | IT | ||
|
All Ring Tech is a Taiwanese company producing advanced automation equipment for semiconductors, LEDs, passive components, and solar industries. |
|||||
| Ransomware | SIMCO Electronics (UPDATE 5/5/2025) id19742 View details | United States | IT | ||
|
SIMCO Electronics is a U.S.-based IT services company headquartered in Santa Clara, California, with a focus on calibration, repair, and software services for manufacturing, life science, healthcare, and technology organizations. The company provides calibration and software support for test and measurement instruments and operates multiple calibration labs serving a broad customer base. Public company profiles also describe SIMCO as a long-established provider founded in 1962. SIMCO Electronics was listed as a ransomware victim associated with bert. |
|||||
| Ransomware | SIMCO Electronics (UPDATE 5/3/2025) id19716 View details | United States | IT | ||
|
SIMCO Electronics is a US-based IT and technology services company headquartered in Santa Clara, California. It provides calibration, repair, and software services for test and measurement instruments used by manufacturing, healthcare, life science, and research organizations. The company says its services support technology organizations and high-technology manufacturers, with operations centered on precision instrument support and related software. In threat-intelligence catalogs, simco.com is listed as a ransomware victim associated with bert. |
|||||
| Ransomware | SIMCO Electronics id19649 View details | United States | IT | ||
|
SIMCO Electronics is a leading provider of calibration and software solutions for technology companies. Founded in 1962 to serve NASA and Silicon Valley firms. |
|||||
| Ransomware | Yozgat City Hospital id19056 View details | Türkiye | Healthcare / Pharma | ||
|
Modern hospital in Yozgat offering quality care and innovation. Patient health is protected — their data, however, is shared globally. |
|||||
| Ransomware | National Ticket Company id18992 View details | United States | Services | ||
|
National Ticket Company – Tickets and wristbands since 1907. |
|||||