Skip to main content
Mallory

Cuba

Also known ascuba

Cuba ransomware is a financially motivated ransomware and extortion threat group active since late 2020. It is also referred to in the provided content as Tropical Scorpius, ColdDraw, and Fidel. The group is described as a ransomware-as-a-service operation and has also been reported by Microsoft as an intrusion set that, since late 2022, showed espionage-related motivations in phishing campaigns affecting defense and government entities in Europe and North America. Reporting in the provided content also notes Google said the group pivoted from financially motivated crime to espionage. Cuba primarily targets organizations in North America and Europe, with victims globally. The content specifically mentions targeting of retailers, manufacturers, critical infrastructure organizations in the United States, an IT services company in Latin America, and defense and government entities in Europe and North America. Additional reporting notes activity against Western targets throughout 2023 and references attacks against Korean companies in 2022. The group uses double extortion, combining ransomware deployment with data exfiltration and public leak-site pressure to coerce cryptocurrency payments. The content states Cuba has accumulated over $100 million in ransom payments and uses bitcoin mixers to obfuscate payment origins. Tradecraft described in the content includes exploitation of public-facing Microsoft Exchange servers, including ProxyLogon and ProxyShell activity; abuse of Veeam Backup & Replication vulnerabilities, including CVE-2023-27532 and prior VBR flaws; exploitation of ZeroLogon (CVE-2020-1472); use of compromised credentials to establish RDP access; creation of hidden local or admin users and enabling RDP for persistence; credential theft with Mimikatz and Meterpreter; attempted privilege escalation with a Zerologon exploit tool; lateral movement with PsExec, WMI, PowerShell, and other LOLBins; and disabling security tools with DefenderControl and BYOVD techniques. The content attributes multiple malware families and tools to Cuba, including custom malware such as BUGHATCH, BURNTCIGAR, Veeamp, and Wedgecut, as well as use of SystemBC, Cobalt Strike, GoToAssist, NetSupport Manager, Mimikatz, Meterpreter, PowerShell, and PsExec. BUGHATCH is described as a downloader/backdoor associated with Cuba ransomware and UNC2596 reporting. BURNTCIGAR is described as a custom tool used to terminate security processes via vulnerable drivers. The group has also used BYOVD techniques involving vulnerable Avast anti-rootkit drivers, and one report notes a dropper installing the ApcHelper.sys kernel driver to stop security product processes. Defense evasion and anti-forensics behaviors mentioned in the content include disguising malware as legitimate software such as 360 Total Security Antivirus and OpenVPN, loading payloads into memory using PowerShell, and deleting artifacts with cmd.exe /c del. The content also notes Cuba has been linked to campaigns using file deletion and masquerading techniques. The provided reporting states evidence suggests Russian-speaking developers or members, but does not establish state sponsorship. The content also notes possible alias or subgroup identity changes, including a recent alias 'V Is Vendetta,' but this is less consistently referenced than Cuba/Tropical Scorpius.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

26 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics34 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1190
Exploit Public-Facing Application
T1566
Phishing
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
TA0002
Execution
1 technique
T1203
Exploitation for Client Execution
TA0003
Persistence
2 techniques
T1546
Event Triggered Execution
T1546.015×2
Component Object Model Hijacking
T1547
Boot or Logon Autostart Execution
T1547.001×2
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
2 techniques
T1546
Event Triggered Execution
T1546.015×2
Component Object Model Hijacking
T1547
Boot or Logon Autostart Execution
T1547.001×2
Registry Run Keys / Startup Folder
TA0005
Stealth
2 techniques
T1036
Masquerading
T1497×2
Virtualization/Sandbox Evasion
TA0006
Credential Access
1 technique
T1555
Credentials from Password Stores
TA0007
Discovery
6 techniques
T1016
System Network Configuration Discovery
T1018
Remote System Discovery
T1082×2
System Information Discovery
T1083
File and Directory Discovery
T1482×2
Domain Trust Discovery
T1497×2
Virtualization/Sandbox Evasion
TA0008
Lateral Movement
1 technique
T1021
Remote Services
T1021.004
SSH
TA0009
Collection
3 techniques
T1005
Data from Local System
T1074
Data Staged
T1560
Archive Collected Data
T1560.001
Archive via Utility
TA0011
Command and Control
4 techniques
T1105×3
Ingress Tool Transfer
T1568
Dynamic Resolution
T1572
Protocol Tunneling
T1573×2
Encrypted Channel
TA0010
Exfiltration
1 technique
T1041×2
Exfiltration Over C2 Channel
TA0040
Impact
1 technique
T1486×3
Data Encrypted for Impact
IOCS

Observables

1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping26

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables1

Domains, IPs, and hashes tied to this actor, refreshed continuously.