logo

CyberVolk Returns | Flawed VolkLocker Brings New Features With Growing Pains

ID: 55e1628c-2b7a-5e52-ac43-6ac991fae899

STIX ID: report--55e1628c-2b7a-5e52-ac43-6ac991fae899

Feed Name: SentinelOne Blog

Threat Score
75/100

Date Published: 2025-12-11

Date Updated: 2026-04-30

Author: Jim Walter

...
...

This report analyzes CyberVolk’s VolkLocker ransomware-as-a-service: Golang-built Windows and Linux payloads with Telegram-based automation and RaaS features. It documents AES-256-GCM encryption using a hardcoded master key (also written in plaintext to %TEMP%), UAC bypass via the ms-settings registry technique, VM/sandbox detection, registry modifications and Defender disabling, persistence copies, a dynamic HTML ransom note with an enforcement timer and destructive routines (shadow copy deletion, profile folder deletion, BSOD), and published IOCs (file hashes, bitcoin address, Telegram bot token). The plaintext master key backup is highlighted as a critical design flaw enabling victim recovery, while the operator ecosystem and Telegram C2 model indicate active, scalable criminal activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.