Uptime Hamster: 11d 15h 22mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Cheerscrypt

Cheerscrypt

0 incidentes 0 paises 0 sectores ransomware CN Ultimo: -
Aliases: DEV-0401, Cheers! Cheers Hacking Team, Emperor Dragonfly, Bronze Starlight, cheers, Night Sky, BRONZE STARLIGHT, Cheers
Ver en IntelTracker → APTTrail →
Cheerscrypt is a multiplatform ransomware family that emerged in May 2022, initially targeting Linux systems, specifically VMware ESXi environments, before a Windows variant appeared in June 2022. The group's primary motivation is financial gain through multi-extortion, demanding payment for decryption and threatening to leak stolen data. Cheerscrypt is linked to the Chinese hacking group known as 'Emperor Dragonfly,' also tracked as Bronze Starlight by Secureworks and DEV-0401 by Microsoft. A distinguishing characteristic of Cheerscrypt is its direct derivation from the leaked Babuk ransomware builder, sharing significant code similarities, and its unique behavior of renaming target files before encryption, which can lead to encryption failure if file permissions are inadequate.

Aliases del actor

DEV-0401Cheers! Cheers Hacking TeamEmperor DragonflyBronze StarlightcheersNight SkyBRONZE STARLIGHTCheers

Actores similares

cheersransomware · 2BRONZE STARLIGHTapt · 0Night Dragonapt · 1night-dragonactor · 1nightskyransomware · 2bronze-highlandactor · 1apt-hackingteamactor · 1BRONZE BUTLERactor · 1the-whois-hacking-teamactor · 1BRONZE HIGHLANDapt · 0
Tipo
ransomware
Pais origen
CN
Motivacion
-
Impacto
26
Actualizado
Sat, 20 Ju

Paises objetivo (SOCRadar)

United KingdomJapanSingaporeTurkeyUnited States

Sectores objetivo (SOCRadar)

Energy & Utilities ConstructionManufacturingTransportation&WarehousingInformation ServicesFinanceProfessional&Technical ServicesEnterprises & HoldingEducational ServicesHealthCare & Social Assistance