cloak

Ransomware
Sourceransomware.live

About the group

Cloak is a ransomware-as-a-service operation active since late 2022, primarily targeting small-to-medium enterprises in Europe — especially Germany — across manufacturing, healthcare, education, and government sectors, with expansion into North American and Asian targets by 2025.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Impact and victims

The group cloak has 2 known ransomware victims. See the most affected sectors and countries and recent victims.

2known victims
2in Brazil
1sectors hit
Most attacked sectors
Energy & Utilities1
Most affected countries
🇧🇷 Brasil2
Recent victims
Nos********om.brNot Found · BR · 2025-07-07
Equatorial EnergiaEnergy & Utilities · BR · 2024-03-24

cloak uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →