Alpha Cyber

Bert Ransomware Mapping the 185.100.157.74 Infrastructure

A new ransomware threat called Bert is targeting organizations across Asia, Europe, and the US, especially in healthcare, technology, and event services.

Alpha Cyber Research1 min readupdated 1 Apr 2026
Bert Ransomware Graph

Bert Ransomware From IP to the whole infrastructure.

A new ransomware threat called Bert is targeting organizations across Asia, Europe, and the US, especially in healthcare, technology, and event services. This group uses both Windows and Linux variants, leveraging simple but effective code and fast, multi-threaded encryption to maximize damage and evade defenses.

Command and Control Server IP: 185.100.157.74

How Bert Operates:
Attackers use a PowerShell loader (start.ps1) to disable security tools, escalate privileges, and download the ransomware payload (payload.exe) directly from 185.100.157.74.

Staging Point:
This IP hosts open directories containing malware components, making it a central hub for Bert’s campaigns.

Russian Hosting:
The IP is registered in Russia, a common tactic to complicate attribution and takedown efforts.

Mapping with VirusTotal
Security teams use VirusTotal to:

Track Bert-related file hashes, PowerShell scripts, and payloads linked to 185.100.157.74

Uncover additional infrastructure, variants, and campaign overlaps

Block and monitor connections to this IP and associated domains

What to Do Now
Block IP 185.100.157.74 at your firewall and monitor for any related activity

Watch for suspicious PowerShell executions and unexpected downloads from external IPs

Update your threat intelligence feeds with Bert IOCs

Need Help?

Alpha Cyber provides:

Real-time monitoring for ransomware infrastructure

Proactive IOC blocking and threat hunting

Incident response and legal guidance for ransomware events

Don’t wait for Bert to strike, secure your network today!

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]