惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
Last Week in AI
Last Week in AI
U
Unit 42
aimingoo的专栏
aimingoo的专栏
Engineering at Meta
Engineering at Meta
博客园 - 聂微东
小众软件
小众软件
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Recent Announcements
Recent Announcements
罗磊的独立博客
MongoDB | Blog
MongoDB | Blog
Stack Overflow Blog
Stack Overflow Blog
博客园_首页
M
MIT News - Artificial intelligence
博客园 - 司徒正美
T
The Blog of Author Tim Ferriss
D
DataBreaches.Net
IT之家
IT之家
C
Check Point Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
T
Tailwind CSS Blog
D
Docker
Microsoft Security Blog
Microsoft Security Blog
Google DeepMind News
Google DeepMind News

RansomLook – Last entries

Panzer · RansomLook Unsafe · RansomLook Barracuda · RansomLook Cry0 · RansomLook Orion · RansomLook Dark Project · RansomLook Orova · RansomLook Gammax · RansomLook Booba Team · RansomLook Exfilsquad · RansomLook Global Secret Group · RansomLook Blackout · RansomLook Syndicate · RansomLook D1r · RansomLook Crpx0 · RansomLook Dataleak · RansomLook Arcus Media · RansomLook Doommageddon · RansomLook Redact · RansomLook Settra · RansomLook Wallstreet · RansomLook Deadlock · RansomLook 3am · RansomLook Direwolf · RansomLook Inc Ransom · RansomLook Qilin · RansomLook Bavacai · RansomLook Killsec3 · RansomLook Black X · RansomLook Coinbase Cartel · RansomLook
Cloak · RansomLook
RansomLook · 2026-06-16 · via RansomLook – Last entries

cloak logo

1/40 degraded parser captcha

151posts (all time)

3last 30 days

3last 7 days

0% avg uptime 30d

Activity · last 30 days last post

cloak logo

Parsing: enabled Captcha in place

View crypto

Description

Cloak is a cybercriminal ransomware group that first appeared publicly in mid-2023, operating with a double-extortion model. It deploys an ARCrypter variant derived from Babuk, delivered via loaders that terminate security and backup services, delete shadow copies, and install encrypted payloads using algorithms like HC-128 combined with Curve25519 key generation. Victims include entities such as the Virginia Attorney General’s Office, whose IT systems were disrupted and whose data (134 GB) was exfiltrated and listed on Cloak’s Tor leak site. Cloak has been linked to other ARCrypter variants like Good Day, sharing victim portals and infrastructure. Its operations reportedly use initial access brokers, phishing, malvertising, and exploit kits for network infiltration.

External Analysis5
Ransom notes3
  • readme_for_unlock.txt txt
  • readme_for_unlock_nov2024.txt txt
  • readme_for_unlock_oct2024.txt txt
Urls1
File servers34
Chat servers4
Activity (interactive) 151
Posts151