Flaw in Hacktivist Ransomware Lets Victims Decrypt Own Files
ID: 04bd6f1a-c6ac-5ca3-86d7-56eab51f406f
STIX ID: report--04bd6f1a-c6ac-5ca3-86d7-56eab51f406f
Feed Name: Dark Reading
Date Published: 2025-12-15
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
SentinelOne analysis details the resurgence of CyberVolk's VolkLocker RaaS — a pro-Russia-aligned hacktivist ransomware service that uses Telegram for automated C2 and offers licenses and malware tools for sale — but contains a critical implementation error: a hard-coded master encryption key that the binary writes to a plaintext backup file in %TEMP%, enabling victim self-recovery; the report also provides IoCs (Windows/Linux indicators, a Bitcoin address, and a Telegram bot token).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
