LIVE
LATEST THREAT: China-Nexus Actor Exploits Critical VMware vCenter Flaw to Deploy Babuk-Derived Ransomware THREAT ALERT ACTIVE
Intelligence DB / Group Profile Cloak

Cloak Ransomware: Group Profile and Why SMBs Are the Primary Target

Cloak ransomware has been operating since 2022 with almost no public profile, quietly building a track record of attacks against small and medium-sized businesses in the US, Germany, and Australia. It relies almost exclusively on initial access brokers rather than its own exploitation capability.

By Ransomware Tracker ·
CloakransomwareSMBinitial access brokerARMattackdouble-extortionWindowsgroup-profile2026
Threat Level
8/10
Sectors Targeted
healthcare
retail
manufacturing
professional-services
education
Ransomware Family
Cloak

Overview

Cloak ransomware has operated since at least late 2022 with a level of public obscurity unusual for a group active across multiple years and geographies. It lacks the brand recognition of Akira, LockBit, or RansomHub, and its operators appear to prefer operational longevity over notoriety. For defenders and threat intelligence teams, that low profile is itself a risk factor — Cloak has been consistently active across the US, Germany, Canada, and Australia targeting small and medium-sized businesses (SMBs), largely beneath the detection threshold of organisations focused on headline RaaS groups.

The group operates a double-extortion model with a dedicated data leak site. Payment demands targeting SMBs are typically in the range of $5,000-$150,000 — substantially lower than enterprise-focused groups — with a rapid escalation model that includes a 72-hour initial demand window before the data publication threat activates.

Initial Access: The IAB Dependency

Cloak’s most operationally distinctive characteristic is its near-complete dependence on initial access brokers (IABs) for network entry. Unlike groups that maintain their own exploitation capability or invest in vulnerability research, Cloak purchases ready-made access from IAB marketplaces — typically remote desktop protocol (RDP) access, VPN credentials, or compromised managed service provider accounts — and begins post-exploitation from an already-established beachhead.

This model has several implications for defenders. First, the network entry method won’t reveal Cloak-specific tradecraft — you’ll see the IAB’s infrastructure, not Cloak’s. Second, if you appear in IAB marketplaces (which can be monitored via threat intelligence services), you’re a Cloak acquisition candidate regardless of whether you’re a named target. Third, because IAB access typically involves valid credentials, initial stages of Cloak intrusions generate minimal alerts.

The favoured IAB access types for Cloak are consistent with the SMB target profile: small businesses with internet-exposed RDP, underpatch VPN appliances (particularly Fortinet and SonicWall products where credential compromise is high), and access brokered through compromised MSP supply chain accounts.

Post-Exploitation Toolset

Once inside, Cloak intrusions follow a relatively consistent pattern. The group has been associated with the use of ARMattack — a commercial post-exploitation tool marketed as a penetration testing framework, available for purchase on underground forums, that offers Cobalt Strike-like functionality at significantly lower cost and with less established detection coverage.

Post-access activity typically spans two to five days in observed intrusions:

Day 1-2: Network reconnaissance using legitimate Windows tools (net commands, ADExplorer for Active Directory enumeration), identification of backup infrastructure, and lateral movement via SMB and RDP to reach domain controllers and file servers.

Day 2-4: Data staging and exfiltration. Cloak uses a combination of WinRAR archive compression and cloud storage uploads (MEGAsync, cloud storage API endpoints). Exfiltration targets prioritise financial records, customer data, and any documents with value for leverage — contracts, legal correspondence, payroll data.

Day 4-5: Ransomware deployment. Cloak’s encryptor targets Windows environments. It uses a combination of symmetric and asymmetric encryption, deletes Volume Shadow Copies via vssadmin before encryption, and modifies the desktop wallpaper as part of the ransom note delivery.

The ransom note directs victims to a Tor-accessible negotiation portal. Unlike some groups, Cloak does not typically employ professional negotiators and the quality of communication with victims has been described by incident responders as inconsistent.

Target Sectors and Geography

Cloak’s victim profile skews heavily toward SMBs across five primary sectors: healthcare (particularly dental practices and small clinic groups), retail, light manufacturing, professional services (accounting, legal, consulting), and education. The common thread is organisations with significant data assets and limited internal security capacity — both conditions that favour ransom payment.

Geographic distribution across documented incidents is approximately 40% US, 30% Germany and DACH region, 15% Australia, with the remainder distributed across the UK, Canada, and Southeast Asia. The disproportionate Germany and DACH representation is unusual among English-language RaaS groups and may reflect specific IAB acquisition patterns or prior targeting campaigns by affiliates.

Data Leak Site

Cloak operates a data leak site (DLS) accessible via Tor that publishes victim data when ransom demands are not met. The site follows a tiered release model: initial publication typically includes proof-of-access samples (partial file trees, financial document previews), with full data publication after the negotiation deadline. Victim counts published on the DLS have varied considerably by period, with activity suggesting the group processes five to fifteen victims per month on average.

Detection Indicators

Intrusions attributed to Cloak or consistent with its IAB-dependent access pattern show the following early indicators:

  • RDP logins from residential or anonymising IP ranges, particularly outside business hours
  • ADExplorer execution or evidence of LDAP enumeration via legitimate tools
  • WinRAR.exe or Zip archive creation touching file paths associated with financial or legal documents
  • MEGAsync client installation or outbound connections to g.api.mega.co.nz
  • ARMattack beacon patterns: HTTP/S beaconing to cloud provider IP ranges with characteristic timing intervals and URI structures
  • vssadmin.exe Delete Shadows /All /Quiet executed from a non-administrative scripted context

Response Considerations

For organisations responding to a Cloak intrusion, three factors specific to the group:

Backup access is typically compromised before encryption. Cloak intrusions consistently target and delete or corrupt backup infrastructure. Assume backups are compromised and verify from a clean, isolated recovery environment before restoring.

The negotiation window is short. The 72-hour window before DLS publication is real in Cloak cases — unlike some groups that extend this deadline repeatedly. If an organisation is in negotiations, the timeline is not as flexible as with enterprise-focused groups.

IAB access may persist post-remediation. Because initial access was acquired via credentials rather than an exploit, the underlying compromised credential source (phished employee, credential stuffing target, compromised MSP) may still be active after the Cloak intrusion is remediated. Full credential rotation and IAB monitoring are necessary components of recovery.

Comparison to Peer Groups

Cloak occupies a specific niche in the ransomware ecosystem: volume-oriented, SMB-focused, IAB-dependent, with low overhead and low profile. It is operationally similar to older STOP/DJVU operators in its business model — high volume, modest demands, limited negotiation capability — but with a more capable toolset and double-extortion mechanism. Organisations that fall below the detection threshold of intelligence programmes focused on Akira, RansomHub, and LockBit are the population most at risk.

// Related Intelligence
Group Profile

Panzer: New RaaS Operation Rapidly Expands Global Victim List

Group Profile

Titan Ransomware: A New RaaS Group Behind a Nine-Victim, Single-Day Strike on Italian Firms

Group Profile

Gunra Ransomware: Conti-Derived RaaS Expands to Five Continents with Multi-Sector Targeting