Notorious Russian cybercriminals return with new ransomware


  • CyberVolk resurfaced with a revamped ransomware-as-a-service model, but its encryption is fundamentally broken
  • VolkLocker’s hard-coded encryption key lets victims recover data for free, undermining the operation
  • The group operates exclusively through Telegram and mixes hacktivism with financially motivated ransomware activity

CyberVolk, a Russian hacktivist group that has been dormant for most of 2025, is back and offering an updated version of its RaaS model to its affiliates. However, there appears to be a gaping structural hole in the encryption engine that renders the entire model harmless.

CyberVolk is a relatively young, pro-Russian hacktivist collective that emerged in 2024. The group’s entire infrastructure is on Telegram, making it a simple process for affiliates to lock files and demand ransom, even if they aren’t too tech-savvy.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top