Cloak Ransomware
0 incidentes
0 paises
0 sectores
ransomware Global Ultimo: -
Cloak ransomware, first detected as a variant around December 2020, established itself as a distinct threat group with public operations and a leak site appearing in August 2023, primarily functioning as a ransomware-as-a-service (RaaS) model. While its precise origins remain elusive, the group extensively uses Initial Access Brokers (IABs) operating on Russian underground forums, suggesting a possible nexus with Eastern European cybercriminal ecosystems. The group's core motivation is financial gain, which they pursue through aggressive double extortion tactics. Cloak distinguishes itself through its technical approach, employing virtual hard disks (VHDs) for payload delivery to circumvent antivirus detection and using the HC-128 algorithm with intermittent encryption for rapid data compromise. A defining characteristic is their exceptionally high ransom payment rate, estimated between 91% and 96%, largely due to intense pressure tactics, including the public release of sensitive exfi
Paises objetivo (SOCRadar)
United Arab Emirates
Austria
Australia
Bahrain
Brazil
Canada
Switzerland
Colombia
Cyprus
Germany
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateEnterprises & HoldingAccommodationManufacturingConstructionPublic Administration