'CyberVolk' hacktivists use ransomware in support of Russian interests
ID: ccf0ee20-47a0-5cd4-9a78-08d25869c558
STIX ID: report--ccf0ee20-47a0-5cd4-9a78-08d25869c558
Feed Name: The Record from Recorded Future News
Threat Score
Researchers have observed CyberVolk, a hacktivist group active since at least March 2024, carrying out DDoS, ransomware, and info-stealer operations against state, public, and critical infrastructure entities in countries including Japan, France, and the U.K.; the group reuses leaked ransomware code (from AzzaSec) and other families (HexaLocker, Parano, LockBit, Chaos) and exfiltrates stolen data via Discord while demanding modest cryptocurrency ransoms.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
