Monday , October 5 2026
CyberVolk

CyberVolk Ransomware Attacks CII In Japan, France, and UK

CyberVolk ransomware, which appeared in May 2024, has increased attacks on government agencies and critical infrastructures in Japan, France, and the UK. CyberVolk, with pro-Russian views, targets countries seen as threats to Russia using advanced encryption that is very hard to break.

This article analyzes CyberVolk’s encryption system, its execution process, and the flaws that hinder recovery without backups.

Major Danish university breached, 200,000 users at risk

Hackers got into the identity and access management system at the Technical University of Denmark (DTU) and downloaded a lot...
Read More
Major Danish university breached, 200,000 users at risk

Microsoft’s X account hijacked to promote Clippy crypto scam

Microsoft's official X account was taken over to promote an unapproved Clippy-themed cryptocurrency. The tech giant’s X account, with 13...
Read More
Microsoft’s X account hijacked to promote Clippy crypto scam

Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

CPanel has put out security updates to fix three problems in cPanel & WHM. These problems could let attackers take...
Read More
Critical cPanel, GitLab AI Gateway and Dell CSM Flaws Enable RCE And Admin Hijacking

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

CyberVolk emerged in May 2024, targeting public sectors in countries with anti-Russian stances. The group uses Telegram to send threats and ransom demands to victims. Notable attacks include Japanese power grids, French research labs, and British scientific groups.

CyberVolk execution flow

CyberVolk seems motivated by geopolitical reasons, supporting pro-Russian views by undermining the technology of rival countries. The ransomware starts with standard user privileges but then runs again with administrator rights to access the entire system.

It then builds an exclusion list to avoid destabilizing critical system directories. Paths containing substrings—such as “Windows,” “Program Files,” and “ProgramData”—are omitted from encryption to maintain system stability and enable persistence after reboot.

Encryption Exclusions:

CyberVolk ignores files with its custom extension and system folders to avoid redundancy and reinfection.

Windows.
Program Files.
ProgramData.
CyberVolk.

The ransomware uses a two-layer symmetric encryption method with AES-256 GCM and ChaCha20-Poly1305. A single symmetric key is generated at process initialization and applied uniformly across all target files. Each file encryption begins with a 12-byte nonce produced by crypto_rand_Read().

This nonce guarantees unique ciphertexts for the same plaintexts. The file is first encrypted with AES-256 GCM, generating ciphertext and an authentication tag, then encrypted again using ChaCha20-Poly1305.

File Structure Changes:

Post-encryption files only contain encrypted data and the ChaCha20-Poly1305 authentication tag, with no nonce or key metadata saved alongside the ciphertext. As a result, offline decryption is impossible.

Encryption in AES-256 GCM mode

After encryption, the ransomware creates a ransom note called READMENOW.txt in the execution folder. A desktop background change and a note prompt victim to enter a fixed decryption key within three tries.

Structural changes between the original file and the encrypted file.

Decryption logic exists but mishandles the nonce, leading to decryption errors. CyberVolk’s ransomware uses strong double-layer encryption with unique, non-storable random values, ensuring that the encrypted data can’t be recovered.

Its pro-Russian orientation and selective targeting of anti-Russian states underscore the geopolitical dimension of its cyber assaults. Organizations need strong backup strategies, keeping offline and controlled copies of important data, and should regularly practice recovery drills to prevent data loss.

Securing backup systems is essential for maintaining operational continuity.

Check Also

Zimbra mail servers

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. …