Berbew malware family
Berbew is a malware family tracked by MalwareAnalyzer by Cyble across 30 publicly analyzed samples. First seen 2026-07-27, most recently 2026-08-23. Observed ATT&CK techniques include T1112, T1059.004, T1105.
Corpus statistics
- Publicly analyzed samples: 30
- First seen: 2026-07-27
- Last seen: 2026-08-23
- Verdicts: malicious 30
- File types: pe 29, elf 1
ATT&CK techniques used by Berbew
Extracted command-and-control infrastructure
- 1.10.7.1 - 1 sample
- 7.0.7.2 - 1 sample
Recent Berbew samples
- 1027d81f04ee69fa9301487eb834bebbd617e0d45b3a52f19e9eae622d082ee5 - malicious (2026-08-23)
- virussign.com_ccf0cf3aab559ccd87ae66853571b580.vir - malicious (2026-08-15)
- a36c9f6bd31e38b7640184d99fb51a819389f8a66f58353466ba61ce9a540fe0 - malicious (2026-08-14)
- virussign.com_a5f999734996c21a85ad63307337a430.vir - malicious (2026-08-14)
- 2b2514c23f6720925a3ce33a5d4e1828fd0c2184a30e95d00f365642f3c70df0 - malicious (2026-08-14)
- virussign.com_50c8acc83d7d454aef4d0c1c8f8f4cc0.vir - malicious (2026-08-13)
- virussign.com_e9225ac812296224fd7f91e9d2cf1870.vir - malicious (2026-08-13)
- virussign.com_b50321c717cbe62bf507cd97a97bcc80.vir - malicious (2026-08-13)
- virussign.com_9d40b24b0c5b6d91fa6037278badbee0.vir - malicious (2026-08-13)
- virussign.com_efd785ae7b4c84a01ca62ba5dc8306b0.vir - malicious (2026-08-12)
- virussign.com_6b320aa4d458ea8888296ce7e0498d60.vir - malicious (2026-08-12)
- 4a9b7667d6aa690843e098e9d840d384f1c8a0000f766fd3cfa6160979c62c32 - malicious (2026-08-12)
- virussign.com_f7d4cf44cfd91dbe6c98784e78b09990.vir - malicious (2026-08-11)
- virussign.com_6daff7830a5c99cfbf0a48bc5d490790.vir - malicious (2026-08-11)
- virussign.com_a21585ea6e81654b76342efd837d2f00.vir - malicious (2026-08-11)
- virussign.com_1d61a87ed6f7fc3b0ee8c13b7bc38670.vir - malicious (2026-08-10)
- virussign.com_3bc54f13147be0ab6ad91b8d49f298d0.vir - malicious (2026-08-10)
- d0f963f80b6c53d7b5c2a8d1d09e647766bcc97db104ac95f4d25a05656fe659 - malicious (2026-08-07)
- c35837c5712703af4eaba46185f34a74c2efe71a42b7859abf73130ac99d2332 - malicious (2026-07-29)
- virussign.com_cfcf48d6a2f4192df1915308187b0e80.vir - malicious (2026-07-28)
- virussign.com_e14397d97c72af1585864b3c082c8890.vir - malicious (2026-07-28)
- virussign.com_80353f69e2562d7bc377e6e206fc8dc0.vir - malicious (2026-07-28)
- virussign.com_322632ba122e2dc784c60f4edff8aca0.vir - malicious (2026-07-28)
- 77a84e50efc64c4248f38bc33aef956f4f8ea899760185f17caed1711da14981.elf - malicious (2026-07-28)
Frequently asked about Berbew
- What is Berbew?
- Berbew is a malware family tracked by MalwareAnalyzer by Cyble across 30 publicly analyzed samples. First seen 2026-07-27, most recently 2026-08-23. Observed ATT&CK techniques include T1112, T1059.004, T1105.
- How many Berbew samples have been analyzed?
- MalwareAnalyzer by Cyble holds 30 publicly analyzed samples attributed to Berbew, first seen 2026-07-27 and most recently 2026-08-23. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Berbew use?
- Across our Berbew samples the most frequently observed techniques are T1112 (14), T1059.004 (1), T1105 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Berbew use?
- Berbew samples in this corpus are distributed as pe (29), elf (1).
- Does Berbew use command-and-control infrastructure?
- Yes. 2 distinct command-and-control indicators have been extracted from Berbew samples, either from static configuration or from traffic captured during sandbox detonation. The full list is published on the family page.
- Is Berbew malicious?
- 30 of 30 analyzed Berbew samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends