Ransomware Intelligence

cloak

Ransomware group profile

23Victims
RussiaSource country
96Impact score

Description

Cloak is a sophisticated ransomware group that emerged in early 2022, notorious for its stealth and advanced evasion methods. Primarily targeting small to medium-sized businesses, they leverage custom malware and zero-day vulnerabilities to conduct their operations, often employing a multi-faceted extortion strategy. Their tactics include double and triple extortion methods, where they threaten data leaks and DDoS attacks on victims who refuse to pay.

Key insights

  • Utilizes zero-day vulnerabilities and custom malware for infiltration and data encryption.
  • Employs spear-phishing for initial access, often using malicious attachments.
  • Known for multi-layered extortion tactics, combining data encryption, theft, and threats of public release.
  • Targets various sectors, notably healthcare and finance, with high payment rates from victims.
  • Increasingly leveraging initial access brokers to penetrate networks of high-value targets.
  • Shifts towards 'triple extortion' by including DDoS attacks against non-compliant victims.

Threat Level & Status Breakdown

For cloak · Based on incidents in selected period

3.4threat level
Aggressiveness9/ 10
Lethality0/ 10
Criticality0.7/ 10
First seenJun 2025
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 18, 2026

Recent activity

Monthly attack count for cloak in the selected period

23Total attacks
5peak in Aug
2.6avg / month
↑ 3 vs first month
JunJulAugSepOctNovDecFebJun02468

Intelligence

IOCs, YARA/Sigma rules, and related families for cloak

  1. a53a9ca8a074c7108f8412c3f8c1fc5d
  2. 77962a384d251f0aa8e3008a88f206d6cb1f7401c759c4614e3bfe865e3e985c
  3. 3928c5874249cc71b2d88e5c0c00989ac394238747bb7638897fc210531b4aab
  4. 7007cf53bcd0083baba202d8ac2d9070
  5. a98dcdee82f6066a4cf2f9d7d161a1bacec8f81d
  6. 94f73b5dc06ba6705fcef3e759413a747049c2949a0c2e44afc03b2f9989cf73
  7. d1038be644a0da3ba05922fa27db4167a6e17451
  8. 1e074d9dca6ef0edd24afb2d13ca4429def5fc5486cd4170c989ef60efd0bbb0
  9. c3804d1329b55a37bfa2f835e1e9bbc7bdb2b260f8e3627c06e02c9f52685d44
View full IOC feed500 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for cloak

Other

T1486

T1486

T1490

T1490

T1078

T1078

T1059

T1059

T1547

T1547

T1021

T1021

T1562

T1562

T1021.001

T1021.001

T1090

T1090

T1003

T1003

T1105

T1105

T1041

T1041

Victims(23)

CompanyDomainCountryIndustryStatusDiscovered
ra-vogeler.dera-vogeler.deDE GermanyProfessional Services
Unknown
about 23 hours ago
ra-*******e
Unknown
3 days ago
d**********e
Unknown
3 days ago
W******S*******D
Unknown
3 days ago
suffolkva.ussuffolkva.usUS United StatesGovernment & Defense
Unknown
4 months ago
****el-p*****.deDE Germany
Unknown
4 months ago
Dinnebiergruppe.dedinnebiergruppe.deDE GermanyRetail & E-Commerce
Unknown
4 months ago
****ne*i***pe.deDE Germany
Unknown
5 months ago
Fitzpatrickhotels.comfitzpatrickhotels.comUS United StatesHospitality
Unknown
6 months ago
****patr**h**s.comNA NamibiaTechnology
Unknown
6 months ago
*****l*****.usUS United States
Unknown
6 months ago
****e-det**.deDE Germany
Unknown
7 months ago
*****.comNA NamibiaRetail & E-Commerce
Unknown
8 months ago
L********den.comNA Namibia
Unknown
8 months ago
TuftsMedicinetuftsmedicine.orgUS United StatesHealthcare
Unknown
10 months ago
Wstg-steuerberater.dewstg-steuerberater.deDE GermanyProfessional Services
Unknown
10 months ago
Tu*******ne
Unknown
10 months ago
Go********lNA Namibia
Unknown
10 months ago
*********.bhBH Bahrain
Unknown
10 months ago
*******roup.roRO Romania
Unknown
10 months ago

Page 1 of 2