VolkLocker, also known as CyberVolk 2.x, is a Golang-based ransomware-as-a-service platform operated by the pro-Russian hacktivist group CyberVolk. It emerged in August 2025 following disruption of the group’s earlier Telegram infrastructure. The service uses Telegram-based automation for affiliate payload generation, command and control, victim management, and ransom-related communications, lowering the barrier to entry for affiliates. VolkLocker has Windows and Linux variants and encrypts selected files using AES-256-GCM. Windows payloads can attempt User Account Control bypasses to obtain elevated privileges, enumerate the host environment and attached drives, identify virtualized or sandboxed environments, disable or evade defensive tooling, and interfere with recovery mechanisms. It can also employ destructive enforcement routines associated with non-payment or unsuccessful decryption attempts. A significant implementation defect in reported builds undermines its extortion capability: a static master encryption key is embedded in the payload and retained in plaintext on affected Windows systems, potentially permitting recovery without payment. CyberVolk has also marketed standalone remote-access and keylogging tools alongside the RaaS offering.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
VolkLocker is a RaaS operation first identified in August 2025, with cross-platform Windows and Linux encryptors.
A new version of VolkLocker, wielded by the pro-Russia RaaS group CyberVolk, has some key enhancements but one fatal flaw. VolkLocker is the ransomware-as-a-service (RaaS) offering of CyberVolk, a group first documented in late 2024 that uses multiple ransomware tools to conduct attacks aligned with the interests of the Russian government.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operation with Windows and Linux encryptors; its leak and exfiltration practices are not established in the reference.
A ransomware strain noted for a cryptographic weakness that, in some cases, enabled victims/defenders to decrypt without paying.
RaaS ransomware with a hard-coded master key implementation flaw enabling free decryption; emerged Aug 2025.
VolkLocker is a ransomware family associated with the CyberVolk collective, known for reusing and modifying leaked ransomware source code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.