CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

BERT Ransomware's First Moves: Kill the VMs, Kill the Backups

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2064

As cited

Copy frozen at (site build).

ransomware

BERT Ransomware's First Moves: Kill the VMs, Kill the Backups

BERT ransomware's initial attacks focus on compromising ESXi hosts to simultaneously disable multiple virtual machines and backup systems, amplifying the impact across an organization's infrastructure. This attack pattern exploits the centralized nature of virtualization environments to maximize damage and operational disruption from a single point of compromise.

Why it matters: Organizations running ESXi environments face rapid, widespread outages if a single host is compromised, as BERT can disable dozens of VMs and backups at once; security teams should prioritize ESXi hardening, segmentation, and immutable backups to prevent total operational failure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

BERT Ransomware's First Moves: Kill the VMs, Kill the Backups

BERT ransomware's initial attacks focus on compromising ESXi hosts to simultaneously disable multiple virtual machines and backup systems, amplifying the impact across an organization's infrastructure. This attack pattern exploits the centralized nature of virtualization environments to maximize damage and operational disruption from a single point of compromise.

Why it matters: Organizations running ESXi environments face rapid, widespread outages if a single host is compromised, as BERT can disable dozens of VMs and backups at once; security teams should prioritize ESXi hardening, segmentation, and immutable backups to prevent total operational failure.

VendorsVMware
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary