Cloak Ransomware Claims Attack on Virginia Attorney General’s Office
ID: 52aba68b-bf4f-52ea-99b9-0dbacccd1533
STIX ID: report--52aba68b-bf4f-52ea-99b9-0dbacccd1533
Feed Name: Halcyon Blog
Cloak ransomware claimed responsibility for an attack on the Virginia Attorney General’s Office that rendered nearly all computer systems and services offline and later resulted in allegedly stolen data being published on the group's leak site; the report profiles Cloak as a RaaS actor using an ARCrypter variant derived from Babuk code, detailing its access methods (IABs, phishing), payload deployment, encryption (HC-128), evasion and persistence techniques, and extortion/double-extortion business model.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
