The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →In a campaign reported by Cisco Talos on November 28, 2016, emails led recipients through a Google redirect and a Tor2Web proxy to a malicious Word document. If a recipient opened the document and enabled its macros, the macro used Windows Command Processor and PowerShell to download and run Cerber 5.0.1. Google was part of the redirect path—not the malware’s author or host—and Tor2Web was a bridge to Tor-hosted files, not ransomware.
How the 2016 Cerber delivery chain worked
Talos said the campaign appeared to have begun on November 24, 2016. Its report describes a sequence in which each step moved the recipient closer to running the ransomware:
- Email lure: Brief messages used subjects such as “Hi,” “How are you,” or “Hello,” with the recipient’s name included in the subject. The body linked to purported pictures, order details, transaction logs, or loan acceptance letters. Talos characterized the emails as basic, not especially polished.
- Google redirect: The link appeared to point to Google, but a Google redirect sent the recipient toward attacker-controlled content. Google’s role in this account was as part of the redirect path; Talos did not say Google authored or endorsed the malware.
- Tor2Web proxy: The redirect used an
onion.toaddress to reach files on a Tor hidden service through a Tor2Web proxy. That arrangement allowed an ordinary browser to access the material without a locally installed Tor client. - Word downloader: The recipient downloaded a malicious Microsoft Word document presenting itself as protected content. According to Talos, execution depended on the recipient opening the document and enabling its macros.
- PowerShell execution: The macro invoked PowerShell through Windows Command Processor. PowerShell downloaded and ran a Cerber PE32 executable from the Tor network via Tor2Web. Talos also documented junk code and command-line obfuscation intended to make detection harder.
- Encryption and extortion: The resulting infection installed Cerber 5.0.1 and encrypted the victim’s files.
Talos reasoned that Tor hosting could make files harder to remove than files on conventional malicious or compromised web servers. It also noted that changing the redirection chain could frustrate reputation-based blocking. These are explanations of the campaign’s design, not claims that the same infrastructure remains active today.
What Tor2Web did—and did not do
Tor2Web provided a way for a browser outside the Tor network to request content hosted as a Tor hidden service. In this chain, it connected the redirect to the Word downloader and, later, to the Cerber executable. It did not itself encrypt files or act as the ransomware.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall#1 Best Overall
Later research helps explain why Tor2Web mattered to Cerber more broadly, but it should not be mistaken for details established by Talos about this specific email campaign. In a 2018 peer-reviewed study, Stijn Pletinckx, Cyril Trap, and Christian Doerr describe Cerber’s control infrastructure as a Tor hidden service directing bots through Tor2Web gateways. Their study says gateway information could change while the hidden service remained harder to locate or disrupt, and analyzes blockchain transaction information used by Cerber installations to discover changing gateway details. That wider control-plane analysis is distinct from the email-to-downloader sequence in Talos’s November 2016 report. Read the Cerber infrastructure study.
What the campaign’s ransom demand meant
The portal observed by Talos demanded 1.3649 BTC, described in the 2016 report as approximately $1,000 at the time, and threatened to raise the amount to 2.7298 BTC after five days. Those figures describe the particular campaign’s demand in 2016; they are neither a current valuation nor a universal Cerber ransom price. Talos’s campaign report gives the contemporaneous details.
How this campaign fits into Cerber’s history
Pletinckx, Trap, and Doerr’s 2018 account describes Cerber as ransomware-as-a-service: affiliates could handle distribution, infection, and extortion while relying on central infrastructure, then receive a share of proceeds. Their version history places the initial release in February 2016, victim redirection through Tor2Web beginning with version 2 in August 2016, a new version 5 delivery mechanism in November 2016, and anti-sandboxing and anti-VM additions in version 6 in June 2017.
As a measure of the infrastructure they observed—not of infections or current activity—the authors recorded approximately 3,701 indicators from July 2016 through October 2017, including wallet addresses, onion domains, gateway domains, and IP addresses. Their dataset contained 3,670 gateway-domain/host combinations, 440 unique IP addresses, and systems across 77 autonomous systems. These counts belong to that study’s monitoring period and methodology, not to Cerber’s present-day infrastructure.
Free tools Windows power users keep installed
One-click scans. No signup required.
A separate 2018 study by Danny Yuxing Huang and coauthors, Tracking Ransomware End-to-end, estimated more than $16 million in likely payments by 19,750 potential victims across ransomware families during its two-year measurement period. The authors separately estimated that South Korean victims likely paid more than $2.5 million to Cerber, which they described as 34% of the Cerber revenue they tracked. These are historical study estimates, not figures for the Talos email campaign or for all Cerber victims. Read the ransomware measurement study.
What organizations can take from the incident
The chain had several control points: email delivery, a user-enabled macro, script-based downloading, access to Tor2Web, and execution of the resulting binary. Talos recommended defense in depth and employee awareness, listing email security, malware protection, web scanning, intrusion prevention, and next-generation firewall controls. These are recommendations in its 2016 report, not current comparative tests of specific products.
- Reduce risky document execution: Review macro policies and restrict macro-enabled files from untrusted sources where business requirements allow. The analyzed chain required the recipient to open the document and enable macros.
- Monitor behavior, not just file names: Look for Office applications spawning command interpreters or PowerShell, and for unexpected script-driven downloads and execution.
- Apply email and web controls together: Inspect links and attachments, and consider how redirects and proxy paths can affect reputation-based blocking.
- Make Tor and Tor2Web decisions deliberately: Blocking access may mitigate this reported chain, but organizations should account for legitimate business needs before imposing a broad restriction.
- Train staff on suspicious lures: A short message and a promised picture, order detail, or financial document still warrant caution, especially when opening a document would require enabling macros.
Talos summarized the organizational lesson this way: “This campaign demonstrates the importance of ensuring that organizations use defense-in-depth defensive architectures to protect their environments as well as the importance of ensuring that employees are properly trained on the email-based threats and proper hygiene.” Cisco Talos, November 28, 2016.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Historical scope
This account concerns one Cerber 5.0.1 email campaign reported in November 2016. Its indicators, infrastructure, and ransom demand should not be treated as current threat intelligence or as representative of every Cerber campaign. The later infrastructure and payment studies cover broader periods and questions than Talos’s campaign analysis.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

