Ransomware Group intelligence
Cloak
ActiveTrack Cloak with 166 published victims and 1 known leak locations in a single intelligence view.
Overview
Cloak is tracked by Breach House as a ransomware group with 166 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Up checked 1h ago | cloak7jpvcb73rtx2ff7kaw2kholu7bdiivxpzbhlny4ybz75dpxckqd.onion |
Top Activity Sectors (13)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Cloak, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: cloak uses PowerShell to execute malicious payloads and stage ransomware operations on compromised hosts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: cloak modifies registry run keys to ensure malware execution upon system reboot for persistence.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: cloak disables security tools such as antivirus software to prevent detection and hinder incident response.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.013 Encrypted/Encoded File Stealth
What they do: cloak encodes victim data with symmetric encryption keys before exfiltration to protect stolen information.
What that means: Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
-
T1070.004 File Deletion Stealth
What they do: cloak deletes Volume Shadow Copies and backup directories via system commands to eliminate recovery options.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: cloak uses remote system discovery to map internal networks and identify high-value targets for encryption.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1049 System Network Connections Discovery Discovery
What they do: cloak queries system network connections to identify active services and potential lateral movement paths.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1135 Network Share Discovery Discovery
What they do: cloak performs network share discovery to identify accessible directories for lateral movement and data targeting.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: cloak encrypts victim files using custom ransomware binaries to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: cloak invokes system recovery inhibition commands to block automatic restoration from backups or snapshots.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (3)
▼The note this group leaves on a compromised machine. Click a filename to read it.
readme_for_unlock.txt
!!! ATTENTION !!! Your network is hacked and files are encrypted. Including the encrypted data we also downloaded other confidential information: Data of your employees, customers, partners, as well as accounting and other internal documentation of your company. All data is stored until you will pay. After payment we will provide you the programs for decryption and we will delete your data. If you refuse to negotiate with us (for any reason) all your data will be put up for sale. What you will face if your data gets on the black market: 1) The personal information of your employees and customers may be used to obtain a loan or purchases in online stores. 2) You may be sued by clients of your company for leaking information that was confidential. 3) After other hackers obtain personal data about your employees, social engineering will be applied to your company and subsequent attacks will only intensify. 4) Bank details and passports can be used to create bank accounts and online wallets through which criminal money will be laundered. 5) You will forever lose the reputation. 6) You will be subject to huge fines from the government. You can learn more about liability for data loss here: https://en.wikipedia.org/wiki/General_Data_Protection_Regulation https://gdpr-info.eu/ Courts, fines and the inability to use important files will lead you to huge losses. The consequences of this will be irreversible for you. Contacting the police will not save you from these consequences, but will only make your situation worse. You can get out of this situation with minimal losses To do this you must strictly observe the following rules: DO NOT Modify, DO NOT rename, DO NOT copy, DO NOT move any files. Such actions may DAMAGE them and decryption will be impossible. DO NOT use any third party or public decryption software, it may also DAMAGE files. DO NOT Shutdown or Reboot the system this may DAMAGE files. DO NOT hire any third party negotiators (recovery/police, etc.) You need to contact us as soon as possible and start negotiations. Instructions for contacting our team: Download & Install TOR browser: https://torproject.org For contact us via LIVE CHAT open our > Website: http://47h4pwve4scndaneljfnxdhzoulgsyfzbgayyonbwztfz74gsdprz5qd.onion > Login: [snip] > Password: [snip] If Tor is restricted in your area, use VPN If you have any problems with LIVE CHAT you can send a message here: > Email: [email protected]
readme_for_unlock_nov2024.txt
!!! ATTENTION !!! Your network is hacked and files are encrypted. Including the encrypted data we also downloaded other confidential information: Data of your employees, customers, partners, as well as accounting and other internal documentation of your company. All data is stored until you will pay. After payment we will provide you the programs for decryption and we will delete your data. If you refuse to negotiate with us (for any reason) all your data will be put up for sale. What you will face if your data gets on the black market: 1) The personal information of your employees and customers may be used to obtain a loan or purchases in online stores. 2) You may be sued by clients of your company for leaking information that was confidential. 3) After other hackers obtain personal data about your employees, social engineering will be applied to your company and subsequent attacks will only intensify. 4) Bank details and passports can be used to create bank accounts and online wallets through which criminal money will be laundered. 5) You will forever lose the reputation. 6) You will be subject to huge fines from the government. You can learn more about liability for data loss here: https://en.wikipedia.org/wiki/General_Data_Protection_Regulation https://gdpr-info.eu/ Courts, fines and the inability to use important files will lead you to huge losses. The consequences of this will be irreversible for you. Contacting the police will not save you from these consequences, but will only make your situation worse. You can get out of this situation with minimal losses To do this you must strictly observe the following rules: DO NOT Modify, DO NOT rename, DO NOT copy, DO NOT move any files. Such actions may DAMAGE them and decryption will be impossible. DO NOT use any third party or public decryption software, it may also DAMAGE files. DO NOT Shutdown or Reboot the system this may DAMAGE files. DO NOT hire any third party negotiators (recovery/police, etc.) You need to contact us as soon as possible and start negotiations. Instructions for contacting our team: Download & Install TOR browser: https://torproject.org For contact us via LIVE CHAT open our > Website: http://7puvv4qtcrigzbxshqibkpibzbmrs6thb7s6uf3tisqfp3t2ddpp66id.onion > Login: [snip] > Password: [snip] If Tor is restricted in your area, use VPN
readme_for_unlock_oct2024.txt
Urgent! Your files have been encrypted - act now to recover them! Greetings, We are a Ransomware Group, and we have successfully infiltrated your system and encrypted your valuable files. We have the only working decryptor, which is the one way to restore your data. Do not attempt to recover the files yourself or involve any third-party organizations, such as law enforcement or cybersecurity firms. Any attempts to do so will result in the permanent deletion of your files without any chance of recovery. To regain access to your files, you must follow these steps: Download & Install TOR browser: https://www.torproject.org/download/ For contact us via LIVE CHAT open our > Website: http://6mw4yczxeqoiq7rgwnpi75qxsjd5jykuutpatflybodwlckoarhfdlid.onion > Login: [snip] > Password: [snip] > Secret Question: [snip] If Tor is restricted in your area, use VPN. We offer a free trial decryption of two insignificant files (<5 MB) to demonstrate our capabilities and build trust. We will provide you with further instructions and the exact amount of ransom required to decrypt your files. Make the payment in Bitcoin to the provided wallet address. Once the payment is confirmed, we will send you the decryptor. Please note that you have a limited time to act before the deadline expires. After that, the decryptor will be destroyed, and your files will remain encrypted forever. Do not ignore this message or attempt to deceive us. We have already infiltrated your system, and we can easily detect any attempts to bypass our ransom demands. Take this situation seriously and act quickly to recover your files. Write to us in the chat to begin the process. Sincerely, Ransomware Group
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (166)
Search, filter and paginate the victim timeline for Cloak. Showing 1–100 of 166.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | ra-vogeler.de id29987 View details | Germany | Finance / Legal / Insurance | — | |
|
Country: germany | Size: 1.1TB | Private | Views: 1 |
|||||
| Ransomware | ra-*******e id29944 View details | Manufacturing / Engineering | — | ||
|
Country: *** | Size: 1.1TB | Private | Views: 1 |
|||||
| Ransomware | d**********e id29945 View details | IT | — | ||
|
Country: *** | Size: 359GB | Private | Views: 0 |
|||||
| Ransomware | W******S*******D id29946 View details | Finance / Legal / Insurance | — | ||
|
Country: *** | Size: 102GB | Private | Views: 0 |
|||||
| Ransomware | suffolkva.us id26779 View details | United States | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | ****el-p*****.de id26778 View details | Germany | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Dinnebiergruppe.de id26657 View details | Germany | Construction / Real Estate | — | |
|
[AI generated] "Dinnebiergruppe.de" is a German company incorporated into the automobile industry. They are authorized dealers for major car brands including Mercedes-Benz, smart, Audi, Porsche, and Volkswagen Commercial Vehicles. The company offers a broad range of services including car sales, leasing, financing, insurance, and extensive car maintenance. Moreover, they are also involved in real estate management, hotel industry, and operate petrol stations. |
|||||
| Ransomware | ****ne*i***pe.de id26086 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Fitzpatrickhotels.com id25221 View details | United States | Hospitality / Food & Beverage / Tourism | — | |
|
[AI generated] Fitzpatrick Hotels operates two boutique hotels in New York City, providing Irish-style hospitality to guests. Established in the late 20th century, the family-owned business primarily caters to those who value warmth, charm, and a touch of old-world elegance. Their hotels, Fitzpatrick Manhattan and Fitzpatrick Grand Central, boast a strategic location, iconic Irish pub-style restaurants, sophisticated amenities, and rooms. |
|||||
| Ransomware | ****patr**h**s.com id24923 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *****l*****.us id24922 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Con*******.com id23969 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ****e-det**.de id23968 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *****.com id23148 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | L********den.com id23147 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | TuftsMedicine id22164 View details | United States | Healthcare / Pharma | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Wstg-steuerberater.de id21636 View details | Germany | Other | — | |
|
Seit über dreißig Jahren betreuen Frank Hoffmann und Stephan Hofmann zuverlässig Mandanten an Rhein und Ruhr und aus dem Bergischen Land. |
|||||
| Ransomware | Tu*******ne id21635 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Go********l id21634 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | *********.bh id21633 View details | Bahrain | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | *******roup.ro id21632 View details | Romania | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Nos********om.br id21011 View details | Brazil | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Ws*******.de id21010 View details | Germany | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Pensions.gov.lk id20854 View details | Sri Lanka | Other | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Productionsaw.com id20493 View details | United States | Manufacturing / Engineering | — | |
|
Country: USA Views: 161 |
|||||
| Ransomware | **********li.com id19767 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bosshard-farben.ch id19248 View details | Switzerland | Communication / Marketing | — | |
|
[AI generated] "Bosshard-farben.ch" is a Swiss company specializing in the sale of floor and wall paints. In addition to interior and exterior paints, they offer lacquers, glazes, plasters, and other painting supplies. They also provide additional products for floor, wall and ceiling design. Renowned for their comprehensive selection, they cater to both professional painters and DIY enthusiasts. |
|||||
| Ransomware | Pe*************.lk id19247 View details | Sri Lanka | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Orl***********.com id19246 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | pea**********.uk id19245 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Pc***********.org id19244 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Bosshard-Farben AG id18990 View details | Switzerland | Communication / Marketing | — | |
|
[IA generated] Swiss company specializing in the production of paints, varnishes, and glazes for building and wood protection, |
|||||
| Ransomware | Oag.state.va.us id18550 View details | United States | Public Sector | — | |
|
[AI generated] N/A |
|||||
| Ransomware | Wr-recht.de id18549 View details | Germany | Finance / Legal / Insurance | — | |
|
[AI generated] "Wr-recht.de" is a German legal advisory firm that specializes in matters of insolvency law, commercial law, and general civil law. The company caters to both private individuals and businesses, offering effective and efficient legal services. They possess extensive experience in guiding clients through legal proceedings, ensuring optimal client representation. |
|||||
| Ransomware | Baltimorecityschools id18548 View details | United States | Education | — | |
|
[AI generated] Baltimore City Public Schools, also known as City Schools, is a public school district in Baltimore, Maryland, United States. It serves the youth of Baltimore and is committed to providing a comprehensive, high-quality education. The district includes elementary, middle, and high schools, and offers specialized programs and initiatives to support students' growth and development. |
|||||
| Ransomware | Fi***************.pa id18547 View details | Panama | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | St***********.nl id18546 View details | Netherlands | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | ba**********.org id17781 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Waggonereng.com id17673 View details | United States | Services | — | |
|
[AI generated] Waggoner Engineering, founded in 1976, is a professional services firm with a focus on engineering, geospatial and consulting services. Their team of multidisciplinary professionals serve clients within sectors like government agencies, industrial organizations, and private sector clients. The key industries they work in include energy, environment, infrastructure, and technology. Their headquarters are in Jackson, Mississippi. |
|||||
| Ransomware | op*********.eu id17672 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | wr********.de id17671 View details | Germany | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | pen********.de id17670 View details | Germany | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | oa*************.us id17669 View details | United States | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Ad***********.ca id17139 View details | Canada | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | Centromedicoenova id17021 View details | Spain | Public Sector | — | |
|
Country: Spain Views: 69 View more /enova Public <100GB |
|||||
| Ransomware | Premierautocredit.com id17001 View details | United States | Finance / Legal / Insurance | — | |
|
Country: USA Views: 53 View more /pac Public 156GB |
|||||
| Ransomware | Kaisersbach.de id16953 View details | Germany | Public Sector | — | |
|
Country: germany Views: 106 View more /kaiser Public <100GB |
|||||
| Ransomware | Neovita.de id16952 View details | Germany | Public Sector | — | |
|
Country: germany Views: 88 View more /neovita Public 227GB |
|||||
| Ransomware | Bwfg.at id16783 View details | Austria | Public Sector | — | |
|
Bwfg.at Country: austria Views: 16 View more /bwfg Public 102GB |
|||||
| Ransomware | pre*************.com id16742 View details | Communication / Marketing | — | ||
|
Country: USA Views: 0 View more /hidden_113 Private 156GB |
|||||
| Ransomware | Wa**********.com id16741 View details | Communication / Marketing | — | ||
|
Country: USA Views: 0 View more /hidden_114 Private |
|||||
| Ransomware | ge*******.com id16740 View details | Communication / Marketing | — | ||
|
Country: Italy Views: 0 View more /hidden_115 Private 271GB |
|||||
| Ransomware | Mai***********.de id16461 View details | Germany | Communication / Marketing | — | |
|
Mai***********.de Country: germany Views: 1 View more /hidden_112 Private <100GB |
|||||
| Ransomware | bac***********.com.au id16460 View details | Australia | Communication / Marketing | — | |
|
bac***********.com.au Country: Australia Views: 2 View more /hidden_111 Private <100GB |
|||||
| Ransomware | Town of Ponoka id16459 View details | Canada | Public Sector | — | |
|
Ponoka.ca Country: Canada Views: 52073 View more /ponoka Public 110GB |
|||||
| Ransomware | Kai*************.de id16220 View details | Germany | Communication / Marketing | — | |
|
Kai*************.de Country: germany Views: 0 View more /hidden_109 Private <100GB |
|||||
| Ransomware | Ne***********.de id16219 View details | Germany | Communication / Marketing | — | |
|
Country: germany Views: 0 View more /hidden_110 Private 227GB |
|||||
| Ransomware | Fmp.gob.pe id16218 View details | Peru | Communication / Marketing | — | |
|
[AI generated] Fmp.gob.pe refers to the Fondo MIVIVIENDA, a Peruvian government initiative aimed at facilitating access to affordable housing. It provides financial products and services to support homeownership, particularly for low- and middle-income families. The organization focuses on promoting sustainable urban development and improving living conditions through accessible mortgage loans and housing programs. |
|||||
| Ransomware | Ukh-hof.de id15964 View details | Germany | Public Sector | — | |
|
Ukh-hof.de Country: Germany Views: 56 View more /ukh Public <100GB |
|||||
| Ransomware | Orthopaedie-hof.de id15965 View details | Germany | Public Sector | — | |
|
Orthopaedie-hof.de Country: Germany Views: 51 View more /ortho Public <100GB |
|||||
| Ransomware | N************.uk id15966 View details | United Kingdom | Communication / Marketing | ||
|
N************.uk Country: United Kingdom Views: 0 View more /hidden_108 Private 125GB |
|||||
| Ransomware | Donnewalddistributing id15866 View details | United States | Public Sector | ||
|
Country: USA Views: 61 View more /donne Public <100GB |
|||||
| Ransomware | o******************v id15772 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | Glo**************.com id15773 View details | Other | |||
|
No additional victim description available. |
|||||
| Ransomware | SCAFF'HOLDING id15774 View details | France | Other | ||
|
No additional victim description available. |
|||||
| Ransomware | Globalresultspr.com id15775 View details | United States | Communication / Marketing | ||
|
Globalresultspr.com Country: USA Public 123GB |
|||||
| Ransomware | don****************.com id15776 View details | United States | Communication / Marketing | ||
|
don****************.com Country: USA Private <100GB |
|||||
| Ransomware | F************.pe id15777 View details | Peru | Communication / Marketing | ||
|
F************.pe Country: Peru Private 221GB |
|||||
| Ransomware | Uk***********.de id15778 View details | Germany | Communication / Marketing | ||
|
Country: Germany Views: 0 Private <100GB |
|||||
| Ransomware | Or*************.de id15779 View details | Germany | Communication / Marketing | ||
|
Country: Germany Views: 0 Private <100GB |
|||||
| Ransomware | Ma************.de id15780 View details | Germany | Communication / Marketing | ||
|
Country: Germany Views: 0 Private 134GB |
|||||
| Ransomware | Bw**********.at id15781 View details | Austria | Communication / Marketing | ||
|
Country: Austria Views: 0 Private 122GB |
|||||
| Ransomware | mm********.com id14900 View details | Ireland | Other | — | |
|
Country: Ireland |
|||||
| Ransomware | Ful************.com id14466 View details | United States | Other | — | |
|
Country: USA |
|||||
| Ransomware | Te***************.net id14465 View details | Italy | Other | — | |
|
Country: italy |
|||||
| Ransomware | Pennvet.com id14452 View details | United States | Other | — | |
|
Country: USA |
|||||
| Ransomware | Wertachkliniken.de id14387 View details | Germany | Other | — | |
|
Country: germany |
|||||
| Ransomware | Pen*****************.com id14154 View details | United States | Other | — | |
|
Country: USA |
|||||
| Ransomware | El**********.hu id14153 View details | United States | Other | — | |
|
Country: USA |
|||||
| Ransomware | we****************.de id14152 View details | Germany | Other | — | |
|
Country: germany |
|||||
| Ransomware | Stjamesplace.org id13958 View details | United States | Other | — | |
|
Country: USA |
|||||
| Ransomware | Dunlop Aircraft Tyres id13927 View details | United Kingdom | Other | — | |
|
Country: United Kingdom |
|||||
| Ransomware | Vibo.dk id13926 View details | Denmark | Other | — | |
|
Country: Denmark |
|||||
| Ransomware | Hvb-ingenieure.de id13925 View details | Germany | Other | — | |
|
Country: germany |
|||||
| Ransomware | Westermans.com id13924 View details | United Kingdom | Other | — | |
|
Country: United Kingdom |
|||||
| Ransomware | Entr**************.fr id13835 View details | France | Other | — | |
|
Country: France |
|||||
| Ransomware | Cb**********.com id13834 View details | Cyprus | Communication / Marketing | — | |
|
Country: Cyprus |
|||||
| Ransomware | St**************.org id13693 View details | United States | Other | — | |
|
Country: USA |
|||||
| Ransomware | Dd*******uk id13645 View details | United Kingdom | Other | — | |
|
Country: United Kingdom |
|||||
| Ransomware | Kalaswire.com id13584 View details | United States | Other | — | |
|
Country: USA |
|||||
| Ransomware | Hv*************.de id13468 View details | Germany | Other | — | |
|
Country: germany |
|||||
| Ransomware | We*******.com id13467 View details | United Kingdom | Other | — | |
|
Country: United Kingdom |
|||||
| Ransomware | Ka******.com id13466 View details | United States | Other | — | |
|
Country: USA |
|||||
| Ransomware | upcli.com id13349 View details | United States | Other | — | |
|
Country: USA |
|||||
| Ransomware | Vi*********.dk id13348 View details | Denmark | Other | — | |
|
Country: Denmark |
|||||
| Ransomware | Abileneisd.org id13253 View details | United States | Other | — | |
|
Country: USA |
|||||
| Ransomware | Dun*****************uk id13252 View details | United Kingdom | Other | — | |
|
Country: United Kingdom |
|||||
| Ransomware | P********.pl id13211 View details | Poland | Other | — | |
|
Country: Poland |
|||||
| Ransomware | Unit*****************.com id13210 View details | United States | Other | — | |
|
Country: USA |
|||||
| Ransomware | Longviewbridge.com id13172 View details | United States | Other | — | |
|
Country: USA |
|||||