HomeSecurityBERT Ransomware disables ESXi virtual machines

BERT Ransomware disables ESXi virtual machines

The BERT ransomware group uses advanced attack tactics through virtualization to maximize damage and hinder organizations' recovery efforts.

See also: Decrypt Linux/ESXi Akira Ransomware files without paying ransom

BERT Ransomware

The emerging BERT has introduced a particularly destructive capability that differentiates it from traditional attacks : the ability to force-shut down ESXi virtual machines before encryption, which significantly complicates recovery processes for targets.

The BERT group, which is monitored by Trend Micro under the name Water Pombero, was first detected in April 2025 and has already become a serious threat to virtual environments in Asia, Europe, and the United States. The most worrying feature of the ransomware lies in its Linux variant, which can detect and forcefully terminate ESXi virtual machines before it begins encrypting files.

This tactical approach ensures that virtual machines cannot continue to operate during the attack, preventing administrators from performing immediate migration or backup of critical systems. The malware executes commands that force the termination of all active virtual machine processes on ESXi hosts, causing maximum operational disruption.

See also: Over 37,000 VMware ESXi servers vulnerable to attacks

Diagram of the VMware vSphere architecture, depicting clients, vCenter Server, application and infrastructure services, and enterprise-level virtualization of physical servers, network, and data storage.

BERT Ransomware disables ESXi virtual machines

The BERT implementation for Linux supports up to 50 concurrent threads for rapid encryption, allowing the ransomware to efficiently process large virtual infrastructures.

When executed without command line parameters, the malware automatically proceeds to terminate virtual machines via built-in ESXi commands, revealing deep knowledge of VMware. The team behind BERT has developed variants that simultaneously target Windows, Linux, and ESXi, enabling coordinated attacks in hybrid IT environments.

On Windows systems, BERT uses PowerShell-based loaders that disable critical security features, such as Windows Defender, firewalls, and User Account Control, before downloading the main malicious payload from infrastructure hosted in Russia.

See also: New Akira Linux Ransomware Attacks VMware ESXi Servers

The group's targeting strategy focuses primarily on the healthcare, technology, and event services sectors, with confirmed victims spanning multiple continents.

Source: cybersecuritynews

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS