216.73.216.6

CyberVolk Ransomware: Analysis of Double Encryption Structure and Disguised Decryption Logic

· Published 12/09/2025 07:44 · Modified 12/09/2025 08:20

Export JSON

Essential information

Published
12/09/2025 07:44
Modified
12/09/2025 08:20
Tags
2025-09-12 aes-256-gcm chacha20-poly1305 cybervolk double encryption geopolitical pro-russian ransomware symmetric key
Related entities
1 intrusion sets (apt), 7 techniques (mitre), 1 malware, 4 others

Description

The , emerging in May 2024, targets public institutions and key infrastructures of anti-Russian countries. It uses a structure with AES-256 GCM and algorithms. The excludes certain files and directories from encryption and uses a generated before the main function starts. A unique nonce is generated for each file encryption, but it's not stored, making decryption impossible. The includes a disguised decryption logic that fails due to an incorrect nonce value. This group communicates via Telegram and has claimed attacks on major facilities in Japan, France, and the UK.

External references