Sunday, March 15, 2026
Law And Order News
  • Home
  • Law and Legal
  • Military and Defense
  • International Conflict
  • Crimes
  • Constitution
  • Cyber Crimes
No Result
View All Result
  • Home
  • Law and Legal
  • Military and Defense
  • International Conflict
  • Crimes
  • Constitution
  • Cyber Crimes
No Result
View All Result
Law And Order News
No Result
View All Result
Home Cyber Crimes

CyberVolk analysis explores ransomware, hacktivism interconnections

CyberVolk analysis explores ransomware, hacktivism interconnections


CyberVolk, a ransomware-as-a-service (RaaS) supplier and pro-Russia hacktivist group, shares a number of similarities and connections to different pro-Russia menace teams, revealing an intertwined community of menace actors that blur the road between politically and financially motivated cybercrime, SentinelOne’s SentinelLabs described in a report printed Monday.

CyberVolk, previously often called GLORIAMIST and Solntsevskaya, first emerged below its present identify in Could 2024 and started claiming ransomware victims in June 2024. The India-based group most not too long ago focused Japanese entities, claiming assaults in opposition to The Japan Basis, Japan Oceanographic Information Heart, Japan Meteorological Company and Tokyo International data System Centre.

Assaults performed by CyberVolk, together with a number of different teams it associates itself with, mirror a mix of economic and political motives, with such teams usually citing geopolitical points as a justification for concentrating on sure international locations with ransomware, SentinelLabs famous.

Teams inhabiting this ecosystem have additionally been shifting focus from distributed denial-of-service (DDoS) assaults to RaaS schemes and different kinds of malware-as-a-service (MaaS), representing an evolution within the toolsets utilized by this assortment of hacktivists.

CyberVolk associates share motives, code

CyberVolk has aligned itself with different hacker teams selling pro-Russian pursuits, equivalent to NONAME057(16), and has additionally promoted different RaaS choices together with Invisible/Doubleface, HexaLocker and Parano.

CyberVolk’s personal ransomware can also be primarily based on the code of a earlier hacktivists-turned-RaaS group known as AzzaSec, which held pro-Russia, anti-Ukraine and anti-Israel beliefs. AzzaSec’s ransomware supply code was leaked in June 2024 and the group was disbanded in August 2024.

The AzzaSec-derived CyberVolk malware targets Home windows machines and is written in C++; it beforehand used AES for file encryption and SHA512 for key era earlier than switching to “ChaCha20-Poly1305 + AES + RSA + Quantum resistant algorithms,” in response to the group’s claims.

When the ransomware is executed, encrypted recordsdata are given the “CyberVolk” file extension and the person’s wallpaper is modified to a picture exhibiting the CyberVolk brand, together with a window displaying a countdown timer and the gang’s cryptocurrency addresses. The ransom demand is usually $1,000 in Bitcoin or USDT with the timer counting down from 5 hours since payload execution.

The Invisible/Doubleface ransomware, which is related to each CyberVolk and the anti-Israel group Moroccan Black Cyber Military, was discovered to have an identical wallpaper and timer performance right down to the identical five-hour time restrict, in response to SentinelLabs. It was decided that Invisible/Doubleface was additionally derived from the leaked AzzaSec code, with Invisible/Doubleface’s personal supply code additionally being leaked not too long ago.

Cybervolk has additionally promoted the HexaLocker RaaS, which was related to the LAPSUS$ hacker group and a hacktivist alliance known as The Holy League, the latter of which is tied to assaults in opposition to Spain after the arrests of NONAME057(16) members by Spanish authorities. Nevertheless, HexaLocker’s developer shut down the operation in October and subsequently supplied to place the ransomware code and infrastructure up on the market.

Hacktivist infighting results in Telegram ousters

CyberVolk, which beforehand performed a lot of its communications with associates and victims by way of Telegram, was banned from the platform in early November 2024 amid rising tensions between numerous hacktivist teams, as is now utilizing X as its important public communications channel. Rival teams aiming to take down or extort each other turned to weaponizing Telegram’s phrases of service and threatening others with experiences and bans, SentinelLabs present in its investigation.

The state of affairs was possible exacerbated by elevated scrutiny on the platform after Telegram CEO Pavel Durov’s arrest. SentinelLabs noticed alleged former members of AzzaSec and one other group known as APTZone claiming accountability for the bans of different teams together with CyberVolk and Doubleface. Additionally they discovered a November put up by RipperSec accusing former members of AzzaSec and Doubleface of extorting and reporting teams related to CyberVolk.

The complicated net of connections between hacktivists and ransomware actors, in addition to conflicts and rivalries between teams, particular person members and former members, paints a sophisticated image of those blended political and financially motivated cybercrime teams.

In the meantime, these teams’ ways and toolsets solely proceed to evolve, with CyberVolk not too long ago creating a webshell and infostealer together with its RaaS providing.

“As teams like CyberVolk leverage brazenly accessible commodity instruments with excessive potential for inflicting harm, they proceed so as to add extra layers of complexity, increasing and revising the instruments as they’re handed round throughout the collective. Ransomware operations will get muddier and improve how a lot cybersecurity groups might want to monitor so as to keep updated on the happenings throughout the cybercrime ecosystem,” SentinelLabs concluded.

The blurring of strains between politically-motivated and financially-motivated teams has additionally been seen within the latest use of Play ransomware by North Korean nation-state actors, and partnerships between Iranian state-sponsored actors and ransomware gangs together with NoEscape, Ransomhouse and ALPHV/BlackCat.

The reuse of leaked ransomware code can also be a well-liked tactic amongst newer ransomware actors, with the widely-used leaked LockBit builder from 2022 not too long ago seen in assaults in opposition to 22 victims by the rising SafePay ransomware gang.



Source link

Tags: analysisCyberVolkexploreshacktivisminterconnectionsransomware
Previous Post

2024 Criminal Legislative Summaries – North Carolina Criminal Law

Next Post

Here's what the weather will be like in Southern California for Thanksgiving Day

Related Posts

Ransomware incident responder gave info to BlackCat cybercriminals during negotiations, DOJ alleges
Cyber Crimes

Ransomware incident responder gave info to BlackCat cybercriminals during negotiations, DOJ alleges

March 15, 2026
How AI And LLMs Are Redefining Cloud Security and Cyber Defense
Cyber Crimes

How AI And LLMs Are Redefining Cloud Security and Cyber Defense

March 14, 2026
Stryker tells SEC that timeline for recovery from cyberattack unknown
Cyber Crimes

Stryker tells SEC that timeline for recovery from cyberattack unknown

March 12, 2026
The Hacking Games Is Recruiting GenZ Talent To Create A Generation Of Cyber Fighters
Cyber Crimes

The Hacking Games Is Recruiting GenZ Talent To Create A Generation Of Cyber Fighters

March 11, 2026
FBI investigating ‘suspicious activities’ on agency network following February incident
Cyber Crimes

FBI investigating ‘suspicious activities’ on agency network following February incident

March 9, 2026
AI Didn't Invent Social Engineering, It Made It Worse
Cyber Crimes

AI Didn't Invent Social Engineering, It Made It Worse

March 5, 2026
Next Post
Here's what the weather will be like in Southern California for Thanksgiving Day

Here's what the weather will be like in Southern California for Thanksgiving Day

The Briefing: Turkey, Trademarks, Copyright, and Cranberry Sauce – IP and Recipes

The Briefing: Turkey, Trademarks, Copyright, and Cranberry Sauce - IP and Recipes

  • Trending
  • Comments
  • Latest
Praxis des Internationalen Privat- und Verfahrensrechts (IPRax) 6/2024: Abstracts

Praxis des Internationalen Privat- und Verfahrensrechts (IPRax) 6/2024: Abstracts

October 31, 2024
Lean Into Our Community as Our Fight Continues | ACS

Lean Into Our Community as Our Fight Continues | ACS

August 24, 2025
Announcements: CfP Ljubljana Sanctions Conference; Secondary Sanctions and the International Legal Order Discussion; The Law of International Society Lecture; CfS Cyber Law Toolkit; ICCT Live Webinar

Announcements: CfP Ljubljana Sanctions Conference; Secondary Sanctions and the International Legal Order Discussion; The Law of International Society Lecture; CfS Cyber Law Toolkit; ICCT Live Webinar

September 29, 2024
Mitigating Impacts to Your Business in a Changing Trade Environment | Customs & International Trade Law Blog

Mitigating Impacts to Your Business in a Changing Trade Environment | Customs & International Trade Law Blog

April 28, 2025
Schools of Jurisprudence and Eminent Thinkers

Schools of Jurisprudence and Eminent Thinkers

June 7, 2025
Better Hope Judges Brush Up Their Expertise On… Everything – See Also – Above the Law

Better Hope Judges Brush Up Their Expertise On… Everything – See Also – Above the Law

June 29, 2024
Maniac customer shoots two, including bartender, after being kicked out of bar

Maniac customer shoots two, including bartender, after being kicked out of bar

March 15, 2026
How Hospitals Helped Erode Reproductive Rights

How Hospitals Helped Erode Reproductive Rights

March 15, 2026
The Enduring Delusion of a War of Civilizations

The Enduring Delusion of a War of Civilizations

March 15, 2026
The Dignity Of Death – India Legal

The Dignity Of Death – India Legal

March 14, 2026
TAAT Global Alternatives (OTCMKTS:TOBAF) and Boyd Group Services (OTCMKTS:BYDGF) Critical Review

TAAT Global Alternatives (OTCMKTS:TOBAF) and Boyd Group Services (OTCMKTS:BYDGF) Critical Review

March 14, 2026
USC and ABC7 criticized for exclusion of all candidates of color in upcoming gubernatorial debate

USC and ABC7 criticized for exclusion of all candidates of color in upcoming gubernatorial debate

March 14, 2026
Law And Order News

Stay informed with Law and Order News, your go-to source for the latest updates and in-depth analysis on legal, law enforcement, and criminal justice topics. Join our engaged community of professionals and enthusiasts.

  • About Founder
  • About Us
  • Advertise With Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2024 Law And Order News.
Law And Order News is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • Law and Legal
  • Military and Defense
  • International Conflict
  • Crimes
  • Constitution
  • Cyber Crimes

Copyright © 2024 Law And Order News.
Law And Order News is not responsible for the content of external sites.