Toggle Side Panel
Abibitumi.com
Site Icon
  • Members Only
  • Store Dashboard
  • Shop
  • Newsletter
  • Affiliate
  • Conference
  • Sankɔfa Journey
  • Quiet Warrior: The BlackNificent Legacy of Nana Kamau Kambon [HD]
  • Log In
Toggle Side Panel
Abibitumi.com
  • MEMBERS ONLY
  • SHOP
  • BECOME AN AFFILIATE
More options

    Shopping Cart

    No products in the cart.

    Sign in Sign up

    Shopping Cart

    No products in the cart.

    • Members Only
    • Store Dashboard
    • Shop
    • Newsletter
    • Affiliate
    • Conference
    • Sankɔfa Journey
    • Quiet Warrior: The BlackNificent Legacy of Nana Kamau Kambon [HD]
    • Log In
    Close search
    Home » Newsfeed
      • Profile Photo
        Profile photo of Yaw Pereko
        Cyber Security Awareness
        Yaw Pereko 7 weeks ago

        21,224 Abibisika (Black Gold) Points
        Badges: UNIA Member – Powered by Abibitumi
        Rank: Unranked Newbie

        Activity observed in the wild – TODAY

        BERT ransomware payload (payload.exe).

        During our pivoting efforts, we identified additional samples uploaded in the wild. Analysis revealed that these samples are older versions, lacking the updated encryption methods and function sequences seen in samples from our internal telemetry. These differences indicate that the threat actors are actively developing and refining the ransomware.

        Over the course of our investigation, we found a PowerShell script (start.ps1) that functions as a loader for the BERT ransomware payload (payload.exe). The script escalates privileges, disables Windows Defender, the firewall, and user account control (UAC), then downloads and executes the ransomware from the remote IP address 185[.]100[.]157[.]74. The exact initial access method remains unclear.

        Interestingly, the mentioned IP address is associated with ASN 39134, which is registered in Russia. While this alone does not establish attribution, the use of Russian infrastructure may indicate a potential connection to threat actors operating in or associated with the region. Notably, start.ps1 acts as the initial execution point for the ransomware.

        https://www.trendmicro.com/pt_br/research/25/g/bert-ransomware-group-targets-asia-and-europe-on-multiple-platforms.html

        trendmicro.com

        BERT Ransomware Group Targets Asia and Europe on Multiple Platforms

        BERT is a newly emerged ransomware group that pairs simple code with effective execution—carrying out attacks across Europe and Asia. In this entry, we examine the group’s tactics, how their variants have evolved, and the tools they use to get … Continue reading

        0 Comments
    • Public
    • All Members
    • My Connections
    • Only Me
    • Public
    • All Members
    • My Connections
    • Only Me
    • Public
    • All Members
    • My Connections
    • Only Me

    Yaw Pereko’s Connections

    Newest | Active | Popular
    • Profile photo of Ɔbenfo Ọbádélé
      95,588 Abibisika (Black Gold) Points
      Badges: UNIA Member – Powered by Abibitumi Abibitumi Mbôngi
      Rank: Abibinwanwa Full Member
      Ɔbenfo Ọbádélé
      active Just now
    • Profile photo of Agya Bakari Kwadwo
      156,040 Abibisika (Black Gold) Points
      Badges: Abibitumi Mbôngi UNIA Member – Powered by Abibitumi MBMotM
      Rank: Abibinwanwa Full Member
      Agya Bakari Kwadwo
      active Just now
    • Profile photo of AFRON8V
      71,525 Abibisika (Black Gold) Points
      Rank: Unranked Newbie
      AFRON8V
      active a minute ago
    • Profile photo of AbdulMalik
      20,065 Abibisika (Black Gold) Points
      Rank: Unranked Newbie
      AbdulMalik
      active a minute ago
    • Profile photo of Kwadwo
      22,510 Abibisika (Black Gold) Points
      Badges: Abibitumi Mbôngi UNIA Member – Powered by Abibitumi
      Rank: Abibinwanwa Full Member
      Kwadwo
      active a minute ago
    See all

    Abibisika Points Purchase

    You need to log in to purchase this.
    • Abibitumi Info Brochure
    • Terms and Conditions
    © 2025 - Kmtyw Social Education Communiversity!
    • Abibitumi Info Brochure
    • Terms and Conditions
    News Feed
    Loading...

    Report

    There was a problem reporting this post.

    Member is harrassing another member
    Contains mature or sensitive content
    Infomation is misinforming and cannot be backed by research
    Activity post is offensive

    Block Member?

    Please confirm you want to block this member.

    You will no longer be able to:

    • See blocked member's posts
    • Mention this member in posts
    • Invite this member to groups
    • Message this member
    • Add this member as a connection

    Please note: This action will also remove this member from your connections and send a report to the site admin. Please allow a few minutes for this process to complete.

    Report

    You have already reported this .

    Insert/edit link

    Enter the destination URL

    Or link to existing content

      No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.