Cuba Ransomware is a financially motivated cybercriminal operation active since late 2019 that conducts human-operated ransomware and double-extortion attacks against enterprise networks. It is also known as the Cuba ransomware gang and is tracked as UNC2596 by Mandiant and REF9019 by Elastic Security. Microsoft has tracked Cuba-deploying activity as DEV-0671, while Mandiant names the ransomware payload COLDDRAW. Its victims include financial services, government, healthcare, critical manufacturing, information technology, and retail organizations. The operation primarily targets the United States, followed by Canada, with additional attacks against organizations in Europe and Asia. As of August 2022, the FBI had identified 101 compromised entities, including 65 in the United States, and approximately $60 million in ransom payments. No affiliation with the Republic of Cuba has been established. Initial-access methods include phishing, Hancitor-delivered malware, compromised credentials, exposed remote services, and exploitation of public-facing applications. The group has exploited Microsoft Exchange vulnerabilities, including ProxyLogon, ProxyShell, and CVE-2022-41080, as well as CVE-2023-27532 in Veeam Backup & Replication. Following compromise, operators establish persistence through backdoors and concealed privileged accounts, harvest credentials with tools such as Mimikatz, conduct Kerberoasting, and exploit vulnerabilities including Zerologon to obtain elevated access. They move laterally using RDP, SMB, PsExec, and Cobalt Strike. Cuba's toolkit includes BUGHATCH, WEDGECUT, BURNTCIGAR, TERMITE, SystemBC, Meterpreter, and NetSupport Manager. BUGHATCH supports host profiling, arbitrary command and payload execution, reflective loading, process injection, and token impersonation. The operators disable endpoint defenses through security-control utilities and kernel-level techniques, including bring-your-own-vulnerable-driver attacks involving vulnerable signed Avast drivers. They exfiltrate sensitive information before encrypting local volumes and network shares, then threaten publication through a dedicated leak site. Analyzed ransomware variants use ChaCha20 with RSA-protected per-file keys, terminate services and processes that interfere with encryption, and employ intermittent encryption to accelerate processing of larger files.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Used a tool to exploit CVE-2020-1472 (also known as “ZeroLogon”) to gain Domain Administrative privileges. This tool and its intrusion attempts have been reportedly related to Hancitor and Qbot.
We observed the execution of the ProxyLogon exploit. Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
Cuba ransomware actors have exploited CVE-2022-24521 in the Windows Common Log File System (CLFS) driver to steal system tokens and elevate privileges.
151 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with ransomware intrusions that used a vulnerable signed driver (aswArPot.sys) as part of BYOVD tradecraft to gain kernel-level capability and disable or tamper with security protections before payload deployment.
Linked to attacks exploiting Veeam Backup & Replication vulnerabilities.
Ransomware gang linked to attacks targeting Veeam Backup & Replication security flaws.
A technically sophisticated ransomware and extortion group, suspected of emerging from Russia, that targets major financial corporations and uses BYOVD techniques, server exploits, initial-access brokers, lateral movement, data exfiltration, and money laundering infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.