logo

Cloak Ransomware Claims Attack on Virginia Attorney General’s Office

ID: 52aba68b-bf4f-52ea-99b9-0dbacccd1533

STIX ID: report--52aba68b-bf4f-52ea-99b9-0dbacccd1533

Feed Name: Halcyon Blog

Threat Score
80/100

Date Published: 2025-03-24

Date Updated: 2026-04-28

...
...

Cloak ransomware claimed responsibility for an attack on the Virginia Attorney General’s Office that rendered nearly all computer systems and services offline and later resulted in allegedly stolen data being published on the group's leak site; the report profiles Cloak as a RaaS actor using an ARCrypter variant derived from Babuk code, detailing its access methods (IABs, phishing), payload deployment, encryption (HC-128), evasion and persistence techniques, and extortion/double-extortion business model.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.