Cloak

Compare
cloak logo
Parsing: enabled Captcha in place

View crypto

Description

Cloak is a cybercriminal ransomware group that first appeared publicly in mid-2023, operating with a double-extortion model. It deploys an ARCrypter variant derived from Babuk, delivered via loaders that terminate security and backup services, delete shadow copies, and install encrypted payloads using algorithms like HC-128 combined with Curve25519 key generation. Victims include entities such as the Virginia Attorney General’s Office, whose IT systems were disrupted and whose data (134 GB) was exfiltrated and listed on Cloak’s Tor leak site. Cloak has been linked to other ARCrypter variants like Good Day, sharing victim portals and infrastructure. Its operations reportedly use initial access brokers, phishing, malvertising, and exploit kits for network infiltration.

External Analysis5
External Analysis
https://www.watchguard.com/wgrd-security-hub/ransomware-tracker/cloak
https://www.thaiCERT.or.th/en/2025/03/25/cloak-ransomware-attacks-virginia-attorney-generals-office/
https://www.halcyon.ai/blog/cloak-ransomware-variant-exhibits-advanced-persistence-evasion-and-vhd-extraction-capabilities
https://www.sentinelone.com/blog/threat-actor-interplay-good-days-victim-portals-and-their-ties-to-cloak/
https://www.cyberint.com/blog/other/cloak-ransomware-whos-behind-the-cloak/
Ransom notes3
Urls1
Url
Status
Screen
Uptime 30d
Health
http://cloak7jpvcb73rtx2ff7kaw2kholu7bdiivxpzbhlny4ybz75dpxckqd.onion Down Screen
37%
File servers34
Url
Status
Screen
Uptime 30d
Health
http://jpef6snenchj3rxgugsozky3i34q66vmcoqy7neyu37xxiwxrad5doid.onion Down
0%
http://glrw7ip5gz2fv2njbiqfvg5uiwavllw5zuixko4yrpj5hta7fjwqpjqd.onion Up Screen
13%
http://vicjwr6abknvcfjomocyb3koloidahc3hidwt5sq2ytwk7yepwfzlsid.onion Down Screen
37%
http://puzhh5aykks65qneqantprbqjt6k5bnigmwqwv6yvkxvkfu4ivva5mid.onion Down Screen
20%
http://piatupks5hai3oafo66xlj2eg2fbzjqy2j7gy3nyhqmnthlrwvrsolad.onion Up Screen
27%
http://necnstpnzuaovjocmiuv7ned7bstczit3kkvotqxl53xo5rfohndlvid.onion Up Screen
33%
http://ey2eak3vq5zbeu4s56m25mm4kvszy2is7gyjs6tsfzmhptbyijkzn2yd.onion Down Screen
20%
http://b53cqorlo7uftd3ymxguwnn7rfoz54ryoojjqxowdsaw2bahvuppntyd.onion Up Screen
30%
http://l3bbtg2p2gp2x43e2nngzkf7ab52k4mef3saowrl6m5notkts7p2vfyd.onion Down Screen
37%
http://vsdp5gqwrunytxw4f6dbxznux66aaewlwyenw3rantba4lwyzbckgfid.onion Down Screen
17%
http://a6gq22ngckken4xksz5ytl66sqeylh45ktke5pnbzfdksw5sfum5lvqd.onion Up Screen
27%
http://nbfxtlikrnicuht5yvvhlujpnh3spzjmek6eujeyck2ws34yytxjdhyd.onion Up Screen
33%
http://ziburuf5kh4phq5i6nmukpke7uruflhlvfexfmjwiwgghapz6ug3ajyd.onion Down Screen
27%
http://am3mzzguimx45wxywpukvwf3gobt3r4bidxzntjpsmqqge4s3vi2vvid.onion Up Screen
27%
http://occwme3xtlnzk3nlhn5ewsgodswrp6pysmmk7kcxqgj4hyiwkhoqcuyd.onion Down Screen
40%
http://qyywpuxysuur4exynwwwhu6nbd2f5vpj3h4tjbltfhwd4blamd4fppqd.onion Up Screen
23%
http://hsn2e745m36crxj2gmnrp432vbsyarhwvq3fgcyus345dp3oqlrltuad.onion Down Screen
27%
http://pbbeck4xcy3jzbu6lv5db3c5n3n44wngmpb5jj3yo4px32mlznziwbid.onion Down Screen
30%
http://hmxt5u75kj5qxqjqhckgaoda6zndgxcazleersyioat4iuq3ldgmkcid.onion Up Screen
30%
http://cii64fki62v2mudocjvgarzlmnpqrfp6xb7korapmdd7qmjpnccgduyd.onion Down Screen
40%
http://jrmayo7rvsx6sbv36djpdge6iwuem67dhccpctera2ykmqr6kplhayad.onion Down Screen
23%
http://ljrswxeei4isir3s5i7xmlzpx6sabmkgd7mvjrimcqwu7rqpn7bdjfad.onion Down Screen
27%
http://qixf7fqw237ikunw4ey22jsc4deltducf6zn4mq4ldyqab3ij3gehlyd.onion Up Screen
20%
http://ztqugnw4upfmd6mu3l6sdz2mfvzxzouhwgqqowyjeedgsmz733dqq2ad.onion Down Screen
30%
http://u66kitj46wmr5onijbbkg7cq45crcs66c563kyqy6klxm5c2nz42ujid.onion Up Screen
33%
http://e7gxrudyx2o733zlernyqqv623wyky5teor5xhnnx2g6dt4vf6jwn2yd.onion Up Screen
37%
http://qx2b2on5phkj4jczfpzfkb5cuhxn7wfqbgdu27pmxyzamoim3jqff6qd.onion Down Screen
30%
http://37izr5yow5d673agew22miyy3inbqncuv7gfp5372yciuzvadqef66yd.onion Down Screen
37%
http://d2wqt4kek62s35hjeankc75nis4zn4e5i6zdtmfkyeevr7fygpf2iiid.onion Down
0%
http://sclj2rax5ljisew3v4msecylzo7iieqw25kcl7io4szei4qcujxixaid.onion Down Screen
30%
http://xyy2fymbdytltylyuicasuvw7vw3gtgm3cvvjskh4jnzfg3gp7dqgnqd.onion Up Screen
33%
http://heac3upmfv33scnkeek64dqdx2cblv7z256aezluyvgtwsxi2o3coiid.onion/ Down Screen
20%
http://uss2a5zyeth7sop57zhgqcyafmnbkmoknps3i7anusze77zppp4bf5yd.onion/ Down Screen
40%
http://67cw3reg2revettu2xfhaaaxhoukctplr6u6mhzri5x6uflet5bq56ad.onion Down Screen
0%
Chat servers4
Url
Status
Screen
Uptime 30d
Health
http://6mw4yczxeqoiq7rgwnpi75qxsjd5jykuutpatflybodwlckoarhfdlid.onion/ Down
0%
http://7puvv4qtcrigzbxshqibkpibzbmrs6thb7s6uf3tisqfp3t2ddpp66id.onion/ Down
0%
http://vir3qwnhwtdriaejfsav6fu5y5ikqlyp5ml345eenlk4pxgabqpf4iid.onion/ Down
0%
http://cfmjv7md32ovswerbaqvxtlznqk647p5coqghbrhyy6euexrffyo6zyd.onion Down
0%
Activity (interactive) 141
Activity charts
Posts141
Date Title Description Screen
Con*******.com Screen
****e-det**.de Screen
*****.com Screen
L********den.com Screen
TuftsMedicine Screen
Wstg-steuerberater.de Screen
Tu*******ne Screen
Go********l Screen
*********.bh Screen
*******roup.ro Screen
Nos********om.br Screen
Ws*******.de Screen
Pensions.gov.lk Screen
Productionsaw.com Country: USA Views: 164
**********li.com Screen
Bosshard-farben.ch Screen
Pe*************.lk Screen
Orl***********.com Screen
pea**********.uk Screen
Pc***********.org Screen
Oag.state.va.us
Wr-recht.de
Baltimorecityschools
Fi***************.pa
St***********.nl
ba**********.org Screen
Waggonereng.com Screen
op*********.eu Screen
wr********.de Screen
pen********.de Screen
oa*************.us Screen
Ad***********.ca
Centromedicoenova Country: Spain Views: 69 View more /enova Public <100GB
Premierautocredit.com Country: USA Views: 53 View more /pac Public 156GB
Kaisersbach.de Country: germany Views: 106 View more /kaiser Public <100GB
Neovita.de Country: germany Views: 88 View more /neovita Public 227GB
Bwfg.at
pre*************.com
Wa**********.com
ge*******.com
Mai***********.de
bac***********.com.au
Town of Ponoka
Kai*************.de
Ne***********.de
Fmp.gob.pe
N************.uk
Orthopaedie-hof.de
Ukh-hof.de
Donnewalddistributing
Bw**********.at
Ma************.de
Or*************.de
Uk***********.de
Globalresultspr.com
don****************.com
F************.pe
SCAFF'HOLDING Screen
Glo**************.com Screen
o******************v Screen
mm********.com Screen
Wertachkliniken.de Screen
Pennvet.com Screen
Ful************.com Screen
Te***************.net Screen
Pen*****************.com Screen
El**********.hu Screen
we****************.de Screen
Kalaswire.com Screen
Dunlop Aircraft Tyres Screen
Vibo.dk Screen
Hvb-ingenieure.de Screen
Westermans.com Screen
Stjamesplace.org Screen
Dd*******uk Screen
Entr**************.fr Screen
Cb**********.com Screen
upcli.com Screen
Vi*********.dk Screen
Hv*************.de Screen
We*******.com Screen
Ka******.com Screen
Dun*****************uk Screen
Longviewbridge.com Screen
Ruland-viersen.de Screen
P********.pl Screen
Unit*****************.com Screen
Mundocar.eu Screen
lo***********.com Screen
ab*******.org Screen
Baeckerei-raddatz.de Screen
Rul**********.de Screen
cli*********.com Screen
bae************.de Screen
Speditionweise.de Screen
Wencor.com Screen
Theharriscenter.org Screen
Mu*****.eu Screen
Cv*****.com Screen
Ce***.com Screen
B*****.hu Screen
Forgepresion.com
Ponoka.ca Screen
Vhs-vaterstetten.de Screen
Gascontec.com Screen
Equatorial Energia Screen
we****.com Screen
The************.org Screen
Sped**********.de Screen
Maas911.com Screen
farwickgrote.de Screen
kvfcu.org Screen
skncustoms.com Screen
euro2000-spa.it Screen
Thenewtrongroup.com Screen
Bankofceylon.co.uk Screen
carranza.on.ca Screen
Arus-gmbh Screen
Sportlab-srl Screen
BONI-PASSAU.DE Screen
lusis-avocats.com Screen
werk33.com Screen
GRIDINSTALLERS.com Screen
surapon.com Screen
mps-24.com Screen
gruppomoba.com Screen
stshcpa.com.tw Screen
ihopmexico.com Screen
Nicer technology Screen
binhamoodah.ae Screen
first-resources-ltd Screen
Sbs-Berlin Screen
imtmro.com Screen
INCOBEC Screen
still95.it Screen
gsh-cargo.com Screen
flamewarestudios.com Screen
ALEZZELPOWER.com Screen
Notaires.fr Screen
Sonabhy.bf Screen
KVFCU.ORG
Note