VolkLocker Operation — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
December 11, 2025
Last Seen
December 11, 2025

VolkLocker Operation is a ransomware threat campaign attributed to Russian-speaking actors.

Overview

VolkLocker Operation is a ransomware threat campaign attributed to Russian-speaking actors. It recently announced a simple ransomware-as-a-service offering, indicating an affiliate-friendly model that lowers technical barriers and could widen its reach. This development underscores a growing trend in ransomware commoditization and potential impact across targets.

Related Threat Clusters

  • CyberVolk Launches New Ransomware Service via Telegram

    CyberVolk, a pro-Russian hacktivist group, has launched a new ransomware-as-a-service called CyberVolk 2.x (VolkLocker) after months of inactivity. This service operates entirely through Telegram, allowing less…

    4 articles · Updated December 11, 2025

Recent Intelligence Reports

  • Russian hackers debut simple ransomware service — Theregister · December 11, 2025

CVSS v3.1 Breakdown