1/40 degraded parser captcha
151posts (all time)
3last 30 days
3last 7 days
0% avg uptime 30d
Activity · last 30 days last post
Parsing: enabled Captcha in place
Description
Cloak is a cybercriminal ransomware group that first appeared publicly in mid-2023, operating with a double-extortion model. It deploys an ARCrypter variant derived from Babuk, delivered via loaders that terminate security and backup services, delete shadow copies, and install encrypted payloads using algorithms like HC-128 combined with Curve25519 key generation. Victims include entities such as the Virginia Attorney General’s Office, whose IT systems were disrupted and whose data (134 GB) was exfiltrated and listed on Cloak’s Tor leak site. Cloak has been linked to other ARCrypter variants like Good Day, sharing victim portals and infrastructure. Its operations reportedly use initial access brokers, phishing, malvertising, and exploit kits for network infiltration.
External Analysis5
Ransom notes3
- readme_for_unlock.txt txt
- readme_for_unlock_nov2024.txt txt
- readme_for_unlock_oct2024.txt txt

























