logo

Halcyon Identifies New Ransomware Operator Volcano Demon Serving Up LukaLocker

ID: 7e073af8-f245-5701-83c7-207179e36fb7

STIX ID: report--7e073af8-f245-5701-83c7-207179e36fb7

Feed Name: Halcyon Blog

Threat Score
78/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

Halcyon researchers report on a new ransomware operator tracked as "Volcano Demon" deploying the LukaLocker encryptor (Windows and Linux variants) in recent attacks: the report details the malware's command-line options, ChaCha8 bulk encryption with Curve25519 ECDH key exchange and footer format, evasion tactics (service/process termination, excluded directories/extensions), IOCs (SHA256 hashes), evidence of data exfiltration for double-extortion, and extortion via direct phone calls to executives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.