Cuba ransomware, also tracked as UNC2596 and with the ransomware payload referred to by Mandiant as COLDDRAW, is a financially motivated ransomware operation first observed around early 2020, with activity increasing through 2020 and 2021 and recurring campaigns documented in 2022 and later. The group has primarily targeted organizations in the United States, followed by Canada, and has been linked to intrusions affecting critical infrastructure entities. Cuba has used both opportunistic and targeted access methods, including exploitation of Microsoft Exchange vulnerabilities such as ProxyShell and ProxyLogon, misconfigured public-facing servers, and earlier access obtained through Hancitor-delivered phishing activity. Cuba operations combine commodity tooling with custom malware. Reported tooling associated with the group includes Cobalt Strike, NetSupport Manager, Mimikatz, Wicker, and custom components such as BUGHATCH, TERMITE, WEDGECUT, and BURNTCIGAR, also known as BurntCigar or PoorTry in related reporting. BUGHATCH is a custom in-memory downloader and backdoor used during Cuba campaigns that supports host fingerprinting, command execution, token impersonation, process injection, and payload delivery. TERMITE has been described as a memory-only dropper used to fetch and load payloads. WEDGECUT has been used for Active Directory reconnaissance. BURNTCIGAR/PoorTry has been used to disable or impair endpoint defenses through bring-your-own-vulnerable-driver tradecraft and kernel-level process termination, and related Cuba intrusions have also abused vulnerable signed drivers to kill protected security processes. Observed Cuba intrusions include exploitation of Exchange servers to deploy web shells and backdoors, credential theft using tools such as Mimikatz, privilege escalation through stolen credentials, lateral movement via RDP, SMB, PsExec, and Cobalt Strike, and broad internal reconnaissance. The group has enumerated local drives and system characteristics, scanned for databases and other valuable assets, and targeted backup infrastructure including Veeam Backup & Replication environments. Cuba has also used utilities and scripts to weaken defenses and prepare systems for encryption, including disabling Windows Defender, terminating security tools, and modifying permissions across local and remote drives. The ransomware payload supports encryption of local volumes, specified paths, network shares, and shares on discovered remote systems. It uses multithreading to accelerate encryption, acquires elevated privileges before terminating processes and services that could interfere with encryption, and has specifically targeted database, virtualization, Outlook, and Microsoft Exchange components. Reported analyses show use of ChaCha20 for file encryption with RSA protecting per-file key material. Cuba has also been observed checking for Russian keyboard language settings and aborting execution on such systems. Cuba is associated with data theft prior to encryption and has operated a leak site to pressure victims. Later variants explicitly threatened publication of stolen data if victims refused to negotiate, indicating double-extortion tactics. The group has been linked to substantial ransom revenues and repeated attacks against enterprise and critical infrastructure victims. Known aliases and tracking names include Cuba, Cuba ransomware, Cuba ransomware gang, UNC2596, and COLDDRAW for the ransomware payload.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
62 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Mandiant has also identified the exploitation of Microsoft Exchange vulnerabilities, including ProxyShell and ProxyLogon, as another access point leveraged by UNC2596 likely as early as August 2021.
Mandiant has also identified the exploitation of Microsoft Exchange vulnerabilities, including ProxyShell and ProxyLogon, as another access point leveraged by UNC2596 likely as early as August 2021.
Next the threat actors attempted to use a file called zero.exe, which is used to exploit the Zerologon vulnerability to escalate privileges.
22 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with ransomware intrusions that used a vulnerable signed driver (aswArPot.sys) as part of BYOVD tradecraft to gain kernel-level capability and disable or tamper with security protections before payload deployment.
Linked to attacks exploiting Veeam Backup & Replication vulnerabilities.
Ransomware gang linked to attacks targeting Veeam Backup & Replication security flaws.
Referenced as a threat actor previously documented using BYOVD techniques in campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.