Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Cloak is a ransomware-as-a-service operation active since late 2022, primarily targeting small-to-medium enterprises in Europe — especially Germany — across manufacturing, healthcare, education, and government sectors, with expansion into North American and Asian targets by 2025. Known victims: 162 2 negotiation log(s) available, 3 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Cloak is a ransomware-as-a-service (RaaS) threat actor targeting small-to-medium enterprises across multiple industries in Europe and expanding into North America and Asia. Their operations since late 2022 have involved extortion through加密ware deployment, with notable campaigns observed as early as August 2023.

Goals & Targeting

Cloak's strategic objectives center on maximizing financial gains through ransomware deployment. They target SMEs due to their vulnerability and potential for higher ransom payments relative to the effort required for compromise. The expansion into diverse regions suggests adaptability and a focus on exploiting varied regional defenses, aligning with their primary motivation of organizational gain.

Enhanced Description

Cloak operates as a RaaS group, leveraging the-as-a-service model to distribute their ransomware. They primarily target SMEs in sectors such as manufacturing, healthcare, education, and government, especially in Germany and other European countries. By 2025, their reach expanded to include North America and Asia. Known for compromising 162 victims, Cloak uses extortion tactics, including negotiation and ransom notes, indicating a structured operational approach focused on financial gain through encrypted data retrieval.

Key Capabilities

  • Ransomware deployment
  • Spear-phishing attacks
  • Internal network traversal
  • Credential dumping techniques
  • Use of common hacking tools like Cobalt Strike and mimikatz

MITRE ATT&CK Tactics

Initial Access
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration
Impact

ATT&CK Techniques

T1546
T1078
T1059.003
T1543.002
T1566.001

Software / Tooling

Cobalt Strike
mimikatz
Custom Ransomware
PowerShell scripts
PsExec

Campaigns & Victims

Cloak's campaigns, starting from August 2023, show a steady operational tempo. They focus on SMEs across various sectors and regions, with notable operations including compromises detected at ra-vogeler.de, indicating dynamic targeting strategies and expansion.

IOC Patterns

  • Ransomware payload hashes (e.g., MD5)
  • Command-and-control communication channels
  • Specific domain patterns in C2 infrastructure

Recommended Actions

  • Implement multi-factor authentication for critical systems.
  • Conduct regular data backups and store them offline securely.
  • Segment networks to limit lateral movement potential.
  • Deploy email filtering solutions to detect phishing attempts.
  • Monitor network traffic for unusual activities, especially encrypted data transfers or file changes.
  • Provide training on ransomware awareness and response strategies.
  • Review and update incident response plans to includeansomware scenarios.

Suggested Tags

ransomware
criminal
RaaS
financial-gain
SME-targeting
European-activity

Confidence Assessment

Moderate confidence based on confirmed campaigns and victims. Some technical details, such as exact tools, may require further confirmation but are consistent with known RaaS tactics.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 13 URL 7

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

4

Campaigns

138

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
Healthcare Targeting
Government Targeting
ransomware
criminal
RaaS
financial-gain
SME-targeting
European-activity

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Aug 24, 2023
Last Seen
Jun 18, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.