CyberVolk Hackers Group With New VolkLocker Payloads Attacks both Linux and Windows Systems
ID: 9ce64001-673a-5591-86a0-b8d168d5925d
STIX ID: report--9ce64001-673a-5591-86a0-b8d168d5925d
Feed Name: cybersecurityNews.com
Threat Score
CyberVolk resurfaced in 2025 with VolkLocker, a Golang-based, cross-platform ransomware-as-a-service that uses an ms-settings UAC bypass for privilege escalation, performs virtual environment detection to evade analysis, and leverages Telegram automation; analysts note embedded test artifacts and lack of obfuscation that create potential recovery and detection opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
