Cerber ransomware targeted to Office 365 users
Summary
This blog post, "Cerber ransomware targeted to Office 365 users", is a blueAPACHE article from 2016 covering security. Hackers target Microsoft’s built-in security to distribute ransomware to Office 365 users It is written for readers evaluating emPOWER Security, Managed Detection and Response. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.
Key facts
| Label | Value |
|---|---|
| Publication year | 2016 |
| Topic | Cerber ransomware targeted to Office 365 users |
| Services referenced | emPOWER Security, Managed Detection and Response |
| Named products or vendors | Microsoft, Office 365, Windows, Fortinet |
| Cited statistic | According to industry estimates, over 57 percent of companies that use Office 365 received at least one copy of the malware hidden in emails, which is no mean feat. |
Article
Hackers target Microsoft’s built-in security to distribute ransomware to Office 365 users
Last week, a massive zero-day attack was launched against Microsoft Office 365 users with a cryptolocker virus called Cerber. According to industry estimates, over 57 percent of companies that use Office 365 received at least one copy of the malware hidden in emails, which is no mean feat.
The ransomware was able to bypass Office 365’s built-in security tools for a short period of time (Microsoft quickly blocked the attack). During this window, the ransomware targeted Office 365 users with spam and phishing emails that contained the malicious malware hidden in attached Word documents. Recipients of the emails were encouraged to open the attachment in Edit mode and Enable Content in order to view the file.
Enabling Content activates the macros in the document, invoking a background download of Cerber ransomware. Once active, Cerber encrypts the victim’s files (local and networked) using the AES-265 and RSA encryption method which is currently unbreakable. The virus then demands a ransom of 1.24 bitcoins (around $US500) to access the decryptor software. There is currently no way to decrypt files for free.
Macros in Word documents (also referred to as Weaponised Office Documents) are not new. Locky ransomware used them, and over $22 million was pilfered from banks using macros with Dridex in 2015.
Cerber was first seen in March this year and is now the third largest threat in the ransomware segment with 24 percent market share. According to Fortinet, only CryptoWall (41 percent) and Locky (34 percent) are greater threats. The rapid expansion of Cerber may be due, at least in part, to the delivery model.
Cerber is offered ‘as a Service’ through a closed underground Russian forum according to cyber intelligence analysts, SenseCy. Branded as Ransomware as a Service (RaaS), affiliates can rent the malware instead of building their own – and developers are further rewarded with bonus commissions from each successful ransom payment. This model reduces the barrier to entry for criminal entrepreneurs, and encourages Cerber developers to continually refine the malware to avoid detection and improve encryption rates.
Avoiding Detection
Malware developers are always exploring different techniques to evade detection, and those behind Cerber are now employing a server-side ‘hash factory’, say Invincea researchers. This means that the server morphs the Cerber payload very frequently to generate unique hashes. In this instance, a new hash is generated every 15 seconds. As signature-based security solutions often rely on the identification of hashes of known malware for detection, the changing payload helps Cerber circumvent security software and reach the target. The concept of changing hashes is not new, but the 15 second frequency makes Cerber stand out from others. Researchers were unable to determine whether the payloads on the server were being programmatically generated locally, or were being generated remotely and uploaded by a script.
Targeted Deployment
After the macros are enabled and Cerber activated, it will check which country the computer is registered as. If registered as Armenia, Azerbaijan, Belarus, Georgia, Kyrgyzstan, Kazakhstan, Moldova, Russia, Turkmenistan, Tajikistan, Ukraine or Uzbekistan, the process will stop and the computer will not be encrypted. If the computer is registered as any other country, Cerber will then install in the Application Data directory and name itself as a random Windows executable. It is most active in the United States (nearly 50 percent of infections), but also targets Taiwan, Japan, Australia, Brazil, Canada, Portugal, Spain, Malaysia, and Germany.
Current Attack
The current Cerber campaign began targeting Microsoft Office 365 users on June 22. Cloud security company Avanan identified that the attack was widely distributed very quickly after the originator confirmed that they could bypass the Office 365 built-in security tools through a private Office 365 mail account. Microsoft quickly identified the problem, circumvented the issue and successfully started blocking the malicious email attachment around the world within hours.
The attack used macros in Word documents to activate the ransomware on victims’ machines. The macros leverage PowerShell, which in turn invoke commands encoded in Base64. Whilst this campaign targeted Office 365 users, it was not restricted to the online version – it had the same impact when using desktop versions of the software.
Once triggered, Cerber configured itself to start automatically when the user logs into windows, execute as a screensaver when the computer is idle, and set a task to execute itself once every minute. It will also show fake system alerts and begin a restart process. The initial restart will be problematic, and a second restart will follow. Researchers are unsure what happens during this multiple restart phase.
When the restart process is complete, the encryption process of the victim’s computer using AES-256 encryption starts. Cerber creates three ransom notes (TXT, HTMLand VBS) named ‘DECRYPT MY FILES’ in every folder as it is encrypted.
The TXT and HTML notes contain the same content. They explain the encryption has occurred, and provide links to Tor and a dedicated Cerber decryption site where ransom payment can be made and the decryption files potentially accessed. Included is the Latin quote “Quod me non necat me fortiorem facit” that translates to “That which does not kill me makes me stronger”.
The VBS note is a script that uses the Microsoft Speech API that is built into Windows to talk directly to the victim.
When the script is executed, the victim’s computer will explain the computer’s files have been encrypted, repeating the message five times. This message can be listened to below:
https://www.blueapache.com/wp-content/uploads/2016/06/Cerber.mp3
The Cerber Decryptor
The ransom notes contain a link to the decrypttozxybarc.onion Tor site. Titled Cerber Decryptor, the site can be accessed in 12 different languages.
The site provides information on the ransom amount, an explanation highlighting the ransom will double if not paid within 7 days, and details on how to pay the ransom. Once a victim makes the bitcoin payment, they are supposedly provided with a download link for their unique decryption files.

Way Forward
According to Kaspersky Security Network, ransomware attacks increased five fold between 2014 and 2016, and are showing no signs of abating. The attacks are also shifting their target from individuals to enterprises with a significant increase in the complexity of malware targeting business networks. Organisations can no longer rely just on built-in security tools – attackers spend considerable time testing and refining malware to ensure it can bypass security before launching full attacks (as we saw in the 2013 Target attack). Organisations should be investigating in a layered defence, augmenting built-in security with additional online tools, next generation firewalls with live sandboxes, and stringent endpoint protection. Equally important is the continued investment in staff education on social engineering and how to identify potential malware threats. If staff can spot malware rather than inadvertently activating it, organisations can mitigate the risks and save days, if not weeks in remediation time and costs. Ransomware threats continue reaching the desktops of the most poorly trained employees within your company. To discuss ways you can easily improve your organisation’s security posture through staff education programs and IT as a Service solutions, contact the blueAPACHE account team.
Related
- emPOWER Security
- emPOWER Security (pillar hub)
- Managed Detection and Response
- emPOWER Microsoft Practice (pillar hub)
- blueAPACHE Security (case study)
Frequently asked questions
What percentage of Office 365-using companies received at least one copy of the Cerber malware, per industry estimates cited?
Over 57 percent.
How did the Cerber ransomware get onto victims' machines in this attack, per the article?
Via spam and phishing emails containing malicious Word document attachments; opening the attachment in Edit mode and enabling content activated macros that triggered a background download of Cerber.
What ransom does Cerber demand, and what happens if it isn't paid within 7 days?
1.24 bitcoins (around US$500) for the decryptor; the article states the ransom doubles if not paid within 7 days.
How does Cerber rank among ransomware threats, per Fortinet data cited in the article?
It is the third-largest ransomware threat with 24 percent market share, behind CryptoWall (41 percent) and Locky (34 percent).
What evasion technique does the article describe Cerber's operators using, and how frequently?
A server-side "hash factory" that morphs the Cerber payload to generate a new, unique hash every 15 seconds, helping it evade signature-based detection.
Which countries does Cerber avoid encrypting, per the article?
Armenia, Azerbaijan, Belarus, Georgia, Kyrgyzstan, Kazakhstan, Moldova, Russia, Turkmenistan, Tajikistan, Ukraine and Uzbekistan.
What three ransom note formats does Cerber create, and what unusual feature does the VBS version have?
TXT, HTML and VBS notes named "DECRYPT MY FILES"; the VBS note uses the Microsoft Speech API to audibly tell the victim their files have been encrypted, repeating the message five times.
How does the article say ransomware attack frequency changed between 2014 and 2016, per Kaspersky data?
Ransomware attacks increased five-fold over that period, according to the Kaspersky Security Network.
Source
- origin post (2016)
Knowledge Base
What is Cerber ransomware and when did the major attack on Office 365 users occur?
Cerber is a cryptolocker virus (ransomware) that was used in a massive zero-day attack launched against Microsoft Office 365 users beginning June 22, according to the blueAPACHE blog post published July 5, 2016.
How many Office 365 companies were affected by the Cerber attack?
According to industry estimates cited in the article, over 57 percent of companies that use Office 365 received at least one copy of the Cerber malware hidden in emails.
How did the Cerber ransomware infect victims' computers?
The ransomware bypassed Office 365's built-in security tools briefly and spread via spam and phishing emails containing malicious Word document attachments. Recipients were encouraged to open the attachment in Edit mode and Enable Content, which activated macros that invoked a background download of Cerber ransomware. The macros leveraged PowerShell, which in turn invoked commands encoded in Base64.
What encryption method does Cerber use and what ransom does it demand?
Cerber encrypts the victim's local and networked files using AES-256 and RSA encryption, which is currently unbreakable. It then demands a ransom of 1.24 bitcoins (around US$500) to access the decryptor software, and there is currently no way to decrypt files for free.
How does the Cerber Ransomware as a Service (RaaS) model work?
Cerber is offered 'as a Service' through a closed underground Russian forum, according to cyber intelligence analysts SenseCy. Under this Ransomware as a Service (RaaS) model, affiliates can rent the malware instead of building their own, and developers earn bonus commissions from each successful ransom payment. This reduces the barrier to entry for criminal entrepreneurs and encourages continual refinement of the malware to avoid detection and improve encryption rates.
How does Cerber avoid detection by security software?
According to Invincea researchers, those behind Cerber use a server-side 'hash factory' that morphs the Cerber payload very frequently to generate unique hashes—a new hash is generated every 15 seconds. Since signature-based security solutions often rely on identifying hashes of known malware, this changing payload helps Cerber circumvent security software.
Which countries does Cerber avoid targeting, and which are most affected?
If a computer is registered in Armenia, Azerbaijan, Belarus, Georgia, Kyrgyzstan, Kazakhstan, Moldova, Russia, Turkmenistan, Tajikistan, Ukraine, or Uzbekistan, Cerber stops and does not encrypt the computer. It is most active in the United States (nearly 50 percent of infections), and also targets Taiwan, Japan, Australia, Brazil, Canada, Portugal, Spain, Malaysia, and Germany.
What market share does Cerber hold among ransomware threats, according to Fortinet?
Cerber was first seen in March 2016 and is the third largest threat in the ransomware segment with 24 percent market share, behind CryptoWall (41 percent) and Locky (34 percent), according to Fortinet.
What happens after Cerber encrypts a victim's files?
Cerber creates three ransom notes (TXT, HTML, and VBS) named 'DECRYPT MY FILES' in every folder as it encrypts. The TXT and HTML notes explain that encryption has occurred and provide links to Tor and a dedicated Cerber decryption site, including the Latin quote 'Quod me non necat me fortiorem facit' ('That which does not kill me makes me stronger'). The VBS note uses the Microsoft Speech API to verbally tell the victim that their files have been encrypted, repeating the message five times.
What is the Cerber Decryptor site and how does the ransom payment process work?
The ransom notes contain a link to the decrypttozxybarc.onion Tor site, titled Cerber Decryptor, accessible in 12 different languages. The site provides information on the ransom amount, explains that the ransom will double if not paid within 7 days, and gives details on how to pay. Once a victim makes the bitcoin payment, they are supposedly provided with a download link for their unique decryption files.
What does the article recommend organisations do to protect against ransomware like Cerber?
The article recommends that organisations invest in a layered defence, augmenting built-in security with additional online tools, next generation firewalls with live sandboxes, and stringent endpoint protection. It also emphasizes continued investment in staff education on social engineering and identifying potential malware threats, noting that Kaspersky Security Network found ransomware attacks increased five-fold between 2014 and 2016 and are shifting focus from individuals to enterprises.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c03b153d68a8eeb8f12_Microsoft-Office-365b.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c05b153d68a8eeb8fe8_Cerber-Screenshot-of-the-virus-as-it-appeared-to-infected-users.png
Cerber - Screenshot of the virus as it appeared to infected users
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c05b153d68a8eeb8fdd_Cerber-html.png
Cerber - html
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c05b153d68a8eeb8fbe_Cerber-decrypt-files-vbs.jpeg
Cerber - decrypt files vbs
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c05b153d68a8eeb8fbb_Cerber-languages-1.png
Cerber - languages
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c05b153d68a8eeb8fe2_Cerber-Tor-site.png
Cerber - tor site
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.