Uptime Hamster: 10d 8h 47mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Cloak Ransomware

Cloak Ransomware

0 incidentes 0 paises 0 sectores ransomware Global Ultimo: -
Ver en IntelTracker → APTTrail →
Cloak ransomware, first detected as a variant around December 2020, established itself as a distinct threat group with public operations and a leak site appearing in August 2023, primarily functioning as a ransomware-as-a-service (RaaS) model. While its precise origins remain elusive, the group extensively uses Initial Access Brokers (IABs) operating on Russian underground forums, suggesting a possible nexus with Eastern European cybercriminal ecosystems. The group's core motivation is financial gain, which they pursue through aggressive double extortion tactics. Cloak distinguishes itself through its technical approach, employing virtual hard disks (VHDs) for payload delivery to circumvent antivirus detection and using the HC-128 algorithm with intermittent encryption for rapid data compromise. A defining characteristic is their exceptionally high ransom payment rate, estimated between 91% and 96%, largely due to intense pressure tactics, including the public release of sensitive exfi

Actores similares

cloakransomware · 166lockbit3ransomware · 2016qilinransomware · 1933akiraransomware · 1524playransomware · 1268clopransomware · 1254lockbit2ransomware · 1002ransomhubransomware · 842incransomransomware · 832alphvransomware · 731
Tecnicas MITRE
T1071.001, T1595, T1490, T1586, T1489, T1078
Tipo
ransomware
Pais origen
Global
Motivacion
-
Impacto
73
Actualizado
Fri, 19 Ju

Paises objetivo (SOCRadar)

United Arab EmiratesAustriaAustraliaBahrainBrazilCanadaSwitzerlandColombiaCyprusGermany

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateEnterprises & HoldingAccommodationManufacturingConstructionPublic Administration