CyberVolk’s VolkLocker Ransomware Flawed, Files Decryptable

CyberVolk's VolkLocker Ransomware-as-a-Service Features Critical Flaws, Targets Windows and Linux with Telegram-Based Automation and a Destructive 48-Hour Deadline

  • The pro-Russian hacktivist group CyberVolk introduced a flawed Ransomware-as-a-service named VolkLocker in August 2025.
  • VolkLocker targets both Windows and Linux systems and encrypts files using AES-256 Galois/Counter Mode.
  • Critical errors in VolkLocker’s design expose master keys, allowing files to be decrypted without paying ransom.
  • The ransomware enforces a 48-hour deadline with a destructive timer that wipes key user folders if conditions are unmet.
  • CyberVolk sells ransomware and Malware tools through Telegram, continuing its operations despite bans and takedowns.

The pro-Russian hacktivist group CyberVolk (also known as GLORIAMIST) relaunched ransomware-as-a-service (RaaS) named VolkLocker in August 2025. The malware targets Windows and Linux systems and is developed in the Golang programming language. This new ransomware variant comes with automation features operated through the Telegram messaging platform, allowing users to manage victims remotely.

- Advertisement -

Operators setting up new VolkLocker builds must provide several parameters, including a Bitcoin address, Telegram bot token, chat ID, encryption deadline, desired file extensions, and self-destruct options, as explained by security researcher Jim Walter in a detailed report. Once executed, VolkLocker escalates privileges, performs system reconnaissance, and identifies files to encrypt based on its configuration. It uses AES-256 encryption in Galois/Counter Mode—a cryptographic method combining encryption and authentication—with unique file extensions such as “.locked” or “.cvolk.”

However, analysis of test samples revealed a significant vulnerability: the ransomware’s master cryptographic keys are hard-coded into the executable files and also saved as plaintext in a file named “system_backup.key” within the %TEMP% directory. This file is never removed, effectively allowing victims to restore their data without paying the ransom.

VolkLocker modifies Windows Registry settings to hinder recovery and analysis processes, deletes volume shadow copies (which are backup snapshots), and terminates security-related processes including Microsoft Defender Antivirus. Notably, the ransomware implements a strict timer that erases the contents of key user directories like Documents, Desktop, Downloads, and Pictures if ransom is not paid within 48 hours or if incorrect decryption keys are entered three times.

CyberVolk charges approximately $800–$1,100 (USD) for either the Windows or Linux versions of VolkLocker, or $1,600–$2,200 for both platforms. Their service includes Telegram-based command-and-control features for victim communication and system management. Since November 2025, the group has also offered a remote access trojan and keylogger at about $500 each, signaling an expansion in their criminal offerings.

- Advertisement -

Originating possibly in India and known for carrying out politically motivated cyberattacks supporting Russian interests, CyberVolk began its RaaS program in June 2024. Despite repeated bans and channel removals on Telegram throughout 2025, the group has restored its operations and grown its range of cybercrime tools. “Defenders should see CyberVolk’s adoption of Telegram-based automation as a reflection of broader trends among politically-motivated threat actors,” Jim Walter stated, highlighting how such groups simplify ransomware deployment and leverage convenient online platforms.source

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Meta Eyes Texas Data Center Site After OpenAI, Oracle Split

The collapse of a major AI data center expansion deal between Oracle and OpenAI...

Former CFO Gets Two Years for $35M Crypto Theft

A Seattle judge sentenced former CFO Nevin Shetty to two years in prison for...

Microsoft Stock Rises on OpenAI Partnership News

Microsoft's partnership with OpenAI has evolved from a 2019 research effort to a major...

Binance Denies $1.7 Billion Iran Sanctions Violations

Binance has firmly denied a U.S. Senator's allegations that it facilitated over $1.7 billion...

Aave Vote Sparks Service Provider Exodus

A contentious vote to fund Aave Labs passed narrowly, causing major service provider ACI...

Must Read

Tutorial: How to Buy a Domain Name Permanently? (Super Easy)

Are you ready to establish a permanent online presence and you want to buy a domain forever?In this tutorial, we'll show you how to...