Skip to main content
  1. Home
  2. Computing
  3. News

The latest ransomware threat announces itself out loud with a creepy computer voice

Add as a preferred source on Google

Cerber, the latest ransomware threat, doesn’t just encrypt all of your files: it also tells you about it, out loud, and repeatedly. It’s like something out of a 90s hacker movie, except this isn’t fake: your files really are all gone until you pay up.

“Attention! Attention! Attention!” is what infected computers will say to their users, using the text-to-speech engine built into Windows. “Your documents, photos, databases, and other files have been encrypted!”

Recommended Videos

Ransomware is malware that infects a users’ computer, then starts encrypting all of the files on it. Assuming users don’t have backups, the only way to get files back is to pay the hackers for a decryption key. Cerber is the latest in a long line of similar attacks, but is unique in a few ways, including the bizarre voice.

Cerber’s modis operandi is outlined in a blog post by Lawrence Abrams of security blog BleepingComputer, which explains that copies of the ransomware are reportedly available for sale on an underground Russian hacker forum. Essentially, this is a franchise model: would-be hackers can use the ransomware, but the original creator also gets a cut.

When the malware spreads to a new machine, it first checks to see if that computer is inside particular countries including Russia and a number of former Soviet block nations. If the laptop is within those borders, the malware won’t do anything.

Then Cerber sets the computer to start in safe mode after the next reboot, and allows itself to run constantly: at boot, as the computer’s screensaver, and every minute just for good measure.

After a few forced reboots, Cerber will scan your computer for certain filetypes including Office documents, photos, PDFs, music, and most other common filetypes, and encrypt them with the near-uncrackable AES-256 algorithm. Cerber can also scan the network for Windows shares, and encrypt files on those machines as well.

Once the ransomware finishes encrypting files, it starts announcing its presence. HTML and TXT files in each encrypted folder explain what has happened, and direct users to install TOR and visit a particular page in order to pay up. For $500, victims can regain access to their files. The VBS files, meanwhile, triggers the aforementioned audio announcement.

There’s currently no way to decrypt the files for free, which means users who really want access to their files are likely to pay up.

If you want to keep yourself safe from threats like this, make sure you have an up-do-date anti-malware application, use common sense while browsing, and make sure you keep backups of all your files.

Justin Pot
Justin's always had a passion for trying out new software, asking questions, and explaining things – tech journalism is the…
AI browsers like Perplexity Comet can be tricked into spilling your password through BioShocking exploit
Six AI browsers were found leaking saved passwords and many of them haven't fixed it yet.
MacBook Air in hand, Comet browser loaded—let’s see what Perplexity’s AI can really do

Security researchers just found a strange way to trick AI browsers into handing over your passwords. They managed to trick AI browser agents into exposing sensitive data like saved passwords, session cookies, and private tokens by disguising the theft as part of a harmless "game."

The technique is called BioShocking, named after the popular video game BioShock, where a brainwashed character is manipulated into believing a false reality. Once an AI browser falls for the same trick, it stops following its own safety rules entirely.

Read more
Google Play’s latest speed boost goes way beyond the phone
Play Store v52.1 targets app install performance across Android devices, including cars, TVs, watches, tablets, and phones.
Google Play Store Photo

Google is rolling out Play Store v52.1 with changes built around a practical Android problem, getting apps installed more smoothly on very different kinds of hardware.

The update focuses on Play Store infrastructure, with Google pointing to stability, performance, and better memory use while a device adds an app. That install path now has to work on phones, tablets, Wear OS watches, Google TV, Android TV, Android Auto, and cars running Android Automotive.

Read more
Peacock Premium Plus joins YouTube as the streaming bundle battle gets messier
The $16.99 subscription brings Peacock’s sports-heavy catalog into YouTube, with account details still unclear.
Adult, Female, Person

Peacock Premium Plus is now available through YouTube Primetime Channels, giving viewers a new way to add a major streaming service inside YouTube.

The $16.99-per-month subscription brings Peacock’s live sports, NBC and Bravo shows, originals, Universal movies, Telemundo programming, and Spanish-language FIFA World Cup 2026 coverage into YouTube’s channel marketplace.

Read more