By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption
Tech News

VolkLocker Ransomware Exposed by Hard-Coded Master Key Allowing Free Decryption

By Viral Trending Content 4 Min Read
Share
SHARE

Dec 15, 2025Ravie LakshmananRansomware / Cybercrime

The pro-Russian hacktivist group known as CyberVolk (aka GLORIAMIST) has resurfaced with a new ransomware-as-a-service (RaaS) offering called VolkLocker that suffers from implementation lapses in test artifacts, allowing users to decrypt files without paying an extortion fee.

According to SentinelOne, VolkLocker (aka CyberVolk 2.x) emerged in August 2025 and is capable of targeting both Windows and Linux systems. It’s written in Golang.

“Operators building new VolkLocker payloads must provide a bitcoin address, Telegram bot token ID, Telegram chat ID, encryption deadline, desired file extension, and self-destruct options,” security researcher Jim Walter said in a report published last week.

Cybersecurity

Once launched, the ransomware attempts to escalate privileges, performs reconnaissance and system enumeration, including checking local MAC address prefixes against known virtualization vendors like Oracle and VMware. In the next stage, it lists all available drives and determines the files to be encrypted based on the embedded configuration.

VolkLocker uses AES-256 in Galois/Counter Mode (GCM) for encryption through Golang’s “crypto/rand” package. Every encrypted file is assigned a custom extension such as .locked or .cvolk.

However, an analysis of the test samples has uncovered a fatal flaw where the locker’s master keys are not only hard-coded in the binaries, but are also used to encrypt all files on a victim system. More importantly, the master key is also written to a plaintext file in the %TEMP% folder (“C:UsersAppDataLocalTempsystem_backup.key”).

Since this backup key file is never deleted, the design blunder enables self-recovery. That said, VolkLocker has all the hallmarks typically associated with a ransomware strain. It makes Windows Registry modifications to thwart recovery and analysis, deletes volume shadow copies, and terminates processes associated with Microsoft Defender Antivirus and other common analysis tools.

However, where it stands out is in the use of an enforcement timer, which wipes the content of user folders, viz. Documents, Desktop, Downloads, and Pictures, if victims fail to pay within 48 hours or enter the wrong decryption key three times.

CyberVolk’s RaaS operations are managed through Telegram, costing prospective customers between $800 and $1,100 for either a Windows or Linux version, or between $1,600 and $2,200 for both operating systems. VolkLocker payloads come with built-in Telegram automation for command-and-control, allowing users to message victims, initiate file decryption, list active victims, and get system information.

Cybersecurity

As of November 2025, the threat actors have advertised a remote access trojan and keylogger, both priced at $500 each, indicating a broadening of their monetization strategy.

CyberVolk launched its own RaaS in June 2024. Known for conducting distributed denial-of-service (DDoS) and ransomware attacks on public and government entities to support Russian government interests, it’s believed to be of Indian origin.

“Despite repeated Telegram account bans and channel removals throughout 2025, CyberVolk has reestablished its operations and expanded its service offerings,” Walter said. “Defenders should see CyberVolk’s adoption of Telegram-based automation as a reflection of broader trends among politically-motivated threat actors. These groups continue to lower barriers for ransomware deployment while operating on platforms that provide convenient infrastructure for criminal services.”

You Might Also Like

iPhone 17e: Price, Release Date, Specs and Features

Pumped Hydro Energy Storage Is Having a Renaissance

New report early stage state supports for Irish tech sector

CISA Flags Critical ASUS Live Update Flaw After Evidence of Active Exploitation

GPT-5.2 vs Gemini 3 Comparison : Strengths, Weaknesses & Best Use Cases

TAGGED: Cyber Security, Cybercrime, Cybersecurity, Data Recovery, encryption, Internet, Linux, Malware, Ransomware, Telegram, Windows
Share This Article
Facebook Twitter Copy Link
Previous Article Bitcoin swings above $94K as crypto faces ‘Netscape’ moment: Finance Redefined
Next Article €70 million to strengthen Europe’s STEM talent pipeline
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Who are the Westerners sanctioned by the EU for spreading Russian propaganda?
World News
Sky Sports to remain home of The Masters in new multi-year extension
Sports
TIAA financial services firm to move from downtown Denver into smaller Glendale office
Business
China's Clean Energy Push is Powering Flying Taxis, Food Delivery Drones and Bullet Trains
World News
Starfield Improvements Were Showcased in a Closed-Door Event for Version 2.0 – Rumour
Gaming News
Uniswap price gains amid potential 100M UNI burn
Crypto
Down over 30% this year, could these 3 UK shares bounce back in 2026?
Business

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Who are the Westerners sanctioned by the EU for spreading Russian propaganda?

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Who are the Westerners sanctioned by the EU for spreading Russian propaganda?
December 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?