CyberVolk Ransomware: Analysis of Double Encryption Structure and Disguised Decryption Logic
Essential information
- Published
- 12/09/2025 07:44
- Modified
- 12/09/2025 08:20
- Tags
- 2025-09-12 aes-256-gcm chacha20-poly1305 cybervolk double encryption geopolitical pro-russian ransomware symmetric key
- Related entities
- 1 intrusion sets (apt), 7 techniques (mitre), 1 malware, 4 others
Description
The CyberVolk ransomware, emerging in May 2024, targets public institutions and key infrastructures of anti-Russian countries. It uses a double encryption structure with AES-256 GCM and ChaCha20-Poly1305 algorithms. The ransomware excludes certain files and directories from encryption and uses a symmetric key generated before the main function starts. A unique nonce is generated for each file encryption, but it's not stored, making decryption impossible. The ransomware includes a disguised decryption logic that fails due to an incorrect nonce value. This pro-Russian group communicates via Telegram and has claimed attacks on major facilities in Japan, France, and the UK.