Ransomware Tracker (Entry #210): CyberVolk
ID: 83625407-bcce-545a-acbf-b613d4c15a7b
STIX ID: report--83625407-bcce-545a-acbf-b613d4c15a7b
Feed Name: WatchGuard Secplicity Blog
**CyberVolk** is a self-proclaimed hacktivist group tied to extortion, DDoS, site defacement, data breaches and ransomware operations; their ransomware is linked to AzzaSec/Babuk derivatives using a hybrid AES+SHA-512 and RSA-4096 scheme, appending extensions like .cvenc/.petik/.CyberVolk, changing desktop wallpapers, and presenting an unclosable decryption modal. Active through 2024 with numerous victims (primarily in Japan and others globally), they claim Russian affiliation but reporting suggests Indian origin with pro-Russian leanings; amounts demanded vary widely and data exfiltration is frequently part of their operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
