Russian hackers debut simple ransomware service, but store keys in plain text
ID: c99f6be7-bced-5b14-a9db-41e3c1661ad9
STIX ID: report--c99f6be7-bced-5b14-a9db-41e3c1661ad9
Feed Name: The Register (Security)
Threat Score
CyberVolk has resumed operations with VolkLocker, a Go-based, cross-platform ransomware-as-a-service run through Telegram that automates payload generation, C2, and affiliate management; it encrypts files with AES-256-GCM and bypasses UAC, but contains a critical flaw—hardcoded master keys written in plaintext to %TEMP%—that may allow victims to recover data, and the group also markets RAT and keylogger tools with listed pricing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
