logo

Ransomware Tracker (Entry #210): CyberVolk

ID: 83625407-bcce-545a-acbf-b613d4c15a7b

STIX ID: report--83625407-bcce-545a-acbf-b613d4c15a7b

Feed Name: WatchGuard Secplicity Blog

Threat Score
75/100

Date Published: 2025-02-21

Date Updated: 2026-05-01

Author: Ryan Estes

...
...

**CyberVolk** is a self-proclaimed hacktivist group tied to extortion, DDoS, site defacement, data breaches and ransomware operations; their ransomware is linked to AzzaSec/Babuk derivatives using a hybrid AES+SHA-512 and RSA-4096 scheme, appending extensions like .cvenc/.petik/.CyberVolk, changing desktop wallpapers, and presenting an unclosable decryption modal. Active through 2024 with numerous victims (primarily in Japan and others globally), they claim Russian affiliation but reporting suggests Indian origin with pro-Russian leanings; amounts demanded vary widely and data exfiltration is frequently part of their operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.