Cerbu malware family
Cerbu is a malware family tracked by MalwareAnalyzer by Cyble across 11 publicly analyzed samples. First seen 2026-08-05, most recently 2026-08-23. Observed ATT&CK techniques include T1071.001, T1056.001.
Corpus statistics
- Publicly analyzed samples: 11
- First seen: 2026-08-05
- Last seen: 2026-08-23
- Verdicts: malicious 11
- File types: pe 11
ATT&CK techniques used by Cerbu
Recent Cerbu samples
- e2d8c36663c3e33973f309b4a07ccdfca72139490fbce0e59a704cc156a41ca4 - malicious (2026-08-23)
- 8a860bb4b2404f9b9011757f6584ea88e037157b4259767b9b872d6aa9bbd61f - malicious (2026-08-23)
- 2fdad07e64abd739e0d403ee1c426e3b4f945211f7b1cc5ae0bae0ad8ebeaf30 - malicious (2026-08-23)
- 9bb20721720042de8067fe01edaaf9b2975d7d262955a999811d2055e23a75ed - malicious (2026-08-21)
- 0911cc000f925cfbe50dd5d5f5821d5aa16b842cc7c4008a5ae2d48e02e7235a - malicious (2026-08-19)
- 01bbca8ffd090ca73cf0475e19daa500d29f150e4606566b24c93de2cdec3d40 - malicious (2026-08-17)
- 4cc0c6227c3fd7e27f0e8b4b4198d8fbd97cb658f4fd96a55d043b021fd4bd47 - malicious (2026-08-15)
- 77665a47ef769a48bf8bf15b0355c2578bd190e6f8ad79e3da07b72bfa111106 - malicious (2026-08-13)
- virussign.com_35e19e76da779c2c172e40199bb32e80.vir - malicious (2026-08-13)
- virussign.com_565c4651ac0b2e83742df659df168110.vir - malicious (2026-08-08)
- ea1ed4ffadff676f39f5bffcd5f90611ae80ed9f141b65eff2c240a95d7cb094 - malicious (2026-08-05)
Frequently asked about Cerbu
- What is Cerbu?
- Cerbu is a malware family tracked by MalwareAnalyzer by Cyble across 11 publicly analyzed samples. First seen 2026-08-05, most recently 2026-08-23. Observed ATT&CK techniques include T1071.001, T1056.001.
- How many Cerbu samples have been analyzed?
- MalwareAnalyzer by Cyble holds 11 publicly analyzed samples attributed to Cerbu, first seen 2026-08-05 and most recently 2026-08-23. This counts public submissions to this platform only, so it is a measure of what we have seen rather than of the family's total prevalence.
- What MITRE ATT&CK techniques does Cerbu use?
- Across our Cerbu samples the most frequently observed techniques are T1071.001 (6), T1056.001 (1). Counts are the number of analyzed samples in which each technique was observed.
- What file types does Cerbu use?
- Cerbu samples in this corpus are distributed as pe (11).
- Is Cerbu malicious?
- 11 of 11 analyzed Cerbu samples were scored malicious by the fused verdict, which combines multi-engine static scanning, YARA and hash reputation with behavior captured during real sandbox detonation. Each report lists every signal that contributed to its score.
Latest analyzed threats · ATT&CK coverage across the corpus · Threat trends