CyberVolk | A Deep Dive into the Hacktivists, Tools and Ransomware Fueling Pro-Russian Cyber Attacks
ID: b52147eb-6bf6-593c-82b4-8b1460cf14ba
STIX ID: report--b52147eb-6bf6-593c-82b4-8b1460cf14ba
CyberVolk (aka GLORIAMIST) is a politically motivated hacktivist collective that adopted leaked AzzaSec ransomware code to run a RaaS and conduct DDoS, ransomware, and information‑stealing operations across multiple countries in 2024; the report documents multiple ransomware families (CyberVolk, Invisible/Doubleface, HexaLocker, Parano), their technical behavior (encryption algorithms, 5‑hour timer via time.dat, process termination, ransom notes), associated stealers and webshells, observed victimization (notably several Japanese entities), and provides IoCs and PDB/DNS artefacts for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
