Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Waymo temporarily suspends service in San Francisco as robotaxis stall due to power outage

Electrical startups raise concerns as EU wateres down 2035 EV targets

Famous Israeli VC John Medved, who was diagnosed with ALS, championed technology to improve his life.

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » VolkLocker ransomware exposed with hardcoded master key, allowing free decryption
Identity

VolkLocker ransomware exposed with hardcoded master key, allowing free decryption

userBy userDecember 15, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

December 15, 2025Ravi LakshmananRansomware/Cybercrime

A pro-Russian hacktivist group known as CyberVolk (also known as GLORIAMIST) has resurfaced with a new ransomware-as-a-service (RaaS) product called VolkLocker, which allows users to decrypt files without paying extortion fees, plagued by a testing artifact implementation error.

According to SentinelOne, VolkLocker (also known as CyberVolk 2.x) will appear in August 2025 and can target both Windows and Linux systems. Written in Golang.

“Operators building new VolkLocker payloads must provide a Bitcoin address, Telegram bot token ID, Telegram chat ID, encryption expiration date, desired file extension, and self-destruct option,” security researcher Jim Walter said in a report published last week.

cyber security

Once launched, the ransomware attempts to escalate privileges and performs reconnaissance and system enumeration, including checking local MAC address prefixes against known virtualization vendors such as Oracle and VMware. The next stage is to list all available drives and decide which files to encrypt based on the embedded configuration.

VolkLocker uses AES-256 in Galois/Counter mode (GCM) for encryption with Golang’s “crypto/rand” package. All encrypted files are assigned a custom extension such as .locked or .cvolk.

However, analysis of test samples revealed a fatal flaw in that the locker’s master key is not only hard-coded into the binary, but is also used to encrypt all files on the victim’s system. More importantly, the master key is also written to a plain text file in the %TEMP% folder (“C:\Users\AppData\Local\Temp\system_backup.key”).

This backup key file is never deleted, allowing for self-healing due to a design error. That said, VolkLocker has all the characteristics typically associated with ransomware. It modifies the Windows registry to interfere with recovery and analysis, remove volume shadow copies, and terminate processes related to Microsoft Defender Antivirus and other popular analysis tools.

However, what stands out is the use of a force timer that clears the contents of user folders. Documents, desktops, downloads, and images if the victim fails to pay within 48 hours or enters the wrong decryption key three times.

CyberVolk’s RaaS operations are managed through Telegram and cost prospective customers between $800 and $1,100 for Windows or Linux versions, and between $1,600 and $2,200 for both operating systems. The VolkLocker payload incorporates Telegram automation for command and control, allowing users to send messages to victims, initiate file decryption, list active victims, and obtain system information.

cyber security

As of November 2025, attackers are advertising remote access trojans and keyloggers, both priced at $500 each, indicating a growing monetization strategy.

CyberVolk launched its own RaaS in June 2024. It is known for conducting distributed denial of service (DDoS) and ransomware attacks against public institutions and government institutions in support of Russian government interests, and is believed to have originated in India.

“Despite repeated bans and channel deletions of Telegram accounts throughout 2025, Cyberbork re-established its business and expanded its service offering,” Walter said. “Defenders should view CyberVolk’s adoption of Telegram-based automation as reflecting a broader trend among politically motivated threat actors. These groups continue to lower the barrier to ransomware deployment while operating on platforms that provide convenient infrastructure for criminal services.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleHow iRobot got lost on his way home
Next Article EU signs groundbreaking agreement to tackle end-of-life vehicles
user
  • Website

Related Posts

Iran’s Infy APT resurfaces with new malware activity after years of silence

December 21, 2025

US Department of Justice charges $54 for ATM jackpotting scheme using Ploutus malware

December 20, 2025

Russian-linked hackers use Microsoft 365 device code phishing to take over accounts

December 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Waymo temporarily suspends service in San Francisco as robotaxis stall due to power outage

Electrical startups raise concerns as EU wateres down 2035 EV targets

Famous Israeli VC John Medved, who was diagnosed with ALS, championed technology to improve his life.

Iran’s Infy APT resurfaces with new malware activity after years of silence

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.