logo

Flaw in Hacktivist Ransomware Lets Victims Decrypt Own Files

ID: 04bd6f1a-c6ac-5ca3-86d7-56eab51f406f

STIX ID: report--04bd6f1a-c6ac-5ca3-86d7-56eab51f406f

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-12-15

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

SentinelOne analysis details the resurgence of CyberVolk's VolkLocker RaaS — a pro-Russia-aligned hacktivist ransomware service that uses Telegram for automated C2 and offers licenses and malware tools for sale — but contains a critical implementation error: a hard-coded master encryption key that the binary writes to a plaintext backup file in %TEMP%, enabling victim self-recovery; the report also provides IoCs (Windows/Linux indicators, a Bitcoin address, and a Telegram bot token).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.