logo

'CyberVolk' hacktivists use ransomware in support of Russian interests

ID: ccf0ee20-47a0-5cd4-9a78-08d25869c558

STIX ID: report--ccf0ee20-47a0-5cd4-9a78-08d25869c558

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2024-11-26

Date Updated: 2026-05-01

...
...

Researchers have observed CyberVolk, a hacktivist group active since at least March 2024, carrying out DDoS, ransomware, and info-stealer operations against state, public, and critical infrastructure entities in countries including Japan, France, and the U.K.; the group reuses leaked ransomware code (from AzzaSec) and other families (HexaLocker, Parano, LockBit, Chaos) and exfiltrates stolen data via Discord while demanding modest cryptocurrency ransoms.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.