With a new ransomware-as-a-service (RaaS) product dubbed VolkLocker, which includes implementation flaws in test artifacts and lets users decrypt files without paying an extortion charge, the pro-Russian hacktivist group CyberVolk (also known as GLORIAMIST) has reappeared.
VolkLocker, also known as CyberVolk 2.x, first appeared in August 2025 and can target Linux and Windows systems, according to SentinelOne. Golang is used for writing.
According to a report released last week by security researcher Jim Walter, operators creating new VolkLocker payloads must supply a bitcoin address, Telegram bot token ID, Telegram chat ID, encryption deadline, preferred file extension, and self-destruct options.
After it is launched, the ransomware tries to increase its privileges, conducts system enumeration and reconnaissance, and compares local MAC address prefixes to those of well-known virtualization providers read more about VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
