The pro-Russian group CyberVolk has made its presence felt again in 2025, launching a full-fledged ransomware called VolkLocker. After months of silence attributed to Telegram crackdowns, the attackers are back with an upgraded strategy and more aggressive targeting techniques.

The group’s reemergence is not simply a continuation of previous operations; it signals the entry of a more organized Ransomware-as-a-Service (RaaS) model, which incorporates automation, cross-platform payloads, and functionality that resembles a corporate product more than an “underground” cybercrime tool.
The new generation of RaaS that leverages Telegram
Unlike previous malware versions, VolkLocker relies heavily on Telegram bots for both attack automation and operational coordination. This allows operators to remotely plan actions, receive real-time alerts, and coordinate supporting accomplices without the need for a stable command-and-control infrastructure.
See also: BlackForce: New phishing kit steals credentials through MitB attacks
The adoption of this practice reveals a clear trend towards greater decentralization in criminal activity, making it harder than ever to counter such tools. The platform acts as a marketplace, allowing even less experienced attackers to carry out attacks with just a few clicks.

Cross-platform architecture and rapid expansion
VolkLocker places particular emphasis on penetrating corporate environments regardless of operating system. With versions written in Golang, the ransomware can target both Windows and Linux infrastructures, a capability that is increasingly common in modern attack tools.
Analysts have noted that the base binaries are distributed without obfuscation, which is seen as a sign of haste, but the creators recommend that contributors use UPX for “lightweight” protection. This suggests that the team is rapidly developing new builds, sometimes sacrificing stability for development speed.
Despite the technical weaknesses, the tool has begun to spread rapidly, with initial analyses by SentinelOne showing that the ransomware even incorporates test artifacts into the code—a feature that reveals the project's immaturity but at the same time the intense development effort.
See also: Fake movie torrent distributes Agent Tesla malware
Privilege Exploitation: A Well-Made Game on Windows
One of the most critical elements that makes VolkLocker dangerous is its careful privilege escalation. Once executed, it scans the environment, looks for opportunities for administrator-level access, and uses a variation of the “ms-settings” bypass method, exploiting an interaction in the Windows registry.
Essentially, it turns a legitimate Windows process into a vehicle for executing ransomware with elevated privileges, without the user receiving any warning. Once this is achieved, VolkLocker gains the ability to modify critical system components, disable services, and corrupt protected areas of the disk.

Environment detection and sandboxing avoidance
The software also features an extensive environment recognition engine. It scans active processes for signs of virtual machines, such as VMware, VirtualBox, QEMU and Hyper‑V, while checking MAC addresses and signatures associated with known virtualization vendors.
If it detects that it is running in a sandbox or lab environment, it stops its operation to avoid analysis. This effectively means that the ransomware is only fully activated in real corporate installations — a tactic increasingly adopted by advanced threat actors.
See also: NANOREMOTE malware abuses Google Drive API
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What does this mean for businesses?
The reemergence of CyberVolk and the creation of VolkLocker show that groups linked to state interests continue to evolve and adopt techniques that are difficult to intercept.
The organizations are called:
- implement strict access controls to the Windows registry,
- monitor suspicious privilege escalation attempts in real time,
- to strengthen their EDR/XDR systems with detection rules for ms-settings bypasses,
- to limit the ability to use automation tools from corporate endpoints.
VolkLocker is yet another example of the ongoing transformation of the ransomware ecosystem. And if one thing is certain, it's that attacks are becoming more agile, more automated, and harder to detect in a timely manner.
