Cloak posted two new claims in the past 30 days, both surfacing within a 48-hour window in mid-June, with the tracked activity concentrated on a single German business-services target (a law firm domain, ra-vogeler.de) alongside partially obscured entries suggesting additional German-linked victims. The group's overall claimed tally remains small at eight victims since it began appearing on trackers, consistent with a low-volume, Europe-focused operation rather than a high-throughput one. Cloak is described in open-source reporting as a ransomware-as-a-service operation running since late 2022 that claims to target small-to-medium enterprises, with Germany cited as a recurring focus and manufacturing, healthcare, education, and government named as sectors of interest; these are claims from the operation's own profile and associated writeups, not independently confirmed here. Catalogued ATT&CK behavior attributed to Cloak includes disabling security tooling prior to encryption and use of double-extortion tactics involving data exfiltration ahead of file-locking. Based on this week's activity, the group's current t