CyberVolk, also known as GLORIAMIST, is a pro-Russian hacktivist collective assessed to originate in India. The group emerged in 2024 and has conducted operations aligned with Russian geopolitical interests, particularly against entities portrayed as opposing Russia or supporting Ukraine. CyberVolk has targeted public-sector and government organizations and has combined disruptive hacktivist activity with overt criminal monetization through ransomware and related tooling. CyberVolk is known for using distributed denial-of-service attacks as well as ransomware. Its ransomware ecosystem has included self-branded payloads derived from leaked and repurposed code associated with AzzaSec, and it has promoted or aligned with related families such as Doubleface/Invisible, HexaLocker, and later VolkLocker. In 2025 the group resurfaced with VolkLocker, also referred to as CyberVolk 2.x, a ransomware-as-a-service platform supporting both Windows and Linux. The operation is heavily centered on Telegram for affiliate management, payload generation, command-and-control, victim interaction, and operational automation, lowering the barrier to entry for less-skilled operators. Observed capabilities include privilege escalation, environmental discovery, virtual-machine and sandbox checks, process termination, disabling or interfering with defensive tooling, deletion of recovery mechanisms, and destructive post-encryption enforcement behavior. CyberVolk has also distributed or advertised additional malware including remote access trojans, keyloggers, infostealers, and webshells. Reporting indicates the group primarily reuses, tweaks, and rebrands leaked or commodity malware rather than developing consistently mature original tooling. CyberVolk has repeatedly exhibited operational and development weaknesses. Earlier ransomware samples embedded decryption material in the code, and VolkLocker builds were reported to hardcode the master encryption key and leave it in plaintext on victim systems, enabling recovery without payment in some cases. These flaws, along with test artifacts in production builds, suggest uneven tradecraft and quality control despite the group’s expanding service model. The group’s activity illustrates the convergence of hacktivism, ransomware, and opportunistic cybercrime: politically framed targeting and pro-Kremlin messaging coexist with affiliate recruitment, ransomware sales, and add-on malware offerings. CyberVolk is best characterized as a politically aligned, pro-Russian hacktivist-ransomware actor with Indian origins and a dominant focus on disruptive and extortion-oriented operations against public-sector targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
30 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Pro-Russian hacktivist collective that deployed ransomware but made a critical implementation error by embedding decryption keys in the code, allowing victims to recover data without paying.
Pro-Russian hacktivist crew that launched a ransomware service but made implementation mistakes by hardcoding master keys into executables, enabling victim recovery without payment.
Pro-Russian hacktivist group operating a ransomware-as-a-service offering (VolkLocker) with noted cryptographic/implementation weaknesses enabling free decryption.
A pro-Russian hacktivist collective known for reusing and rebranding leaked ransomware code, recently active with VolkLocker.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.