REF9019 is a financially motivated ransomware and extortion cluster associated with Cuba Ransomware, also tracked in reporting connected to UNC2596 activity. It has targeted retail and manufacturing organizations in North America and Europe. The group conducts double-extortion operations, stealing sensitive data before encrypting victim systems and threatening public disclosure through a leak site. REF9019 activity has been linked to compromise of public-facing Microsoft Exchange servers, including observed exploitation consistent with ProxyLogon; exploitation of ProxyShell and use of access brokers have also been considered as possible initial-access mechanisms. Following compromise, the operators establish persistence by creating concealed local administrator accounts, enabling Remote Desktop Protocol access, and using scheduled tasks. They use SystemBC, NetSupport Manager, GoToAssist, Cobalt Strike, Meterpreter, Mimikatz, and BUGHATCH during post-compromise operations. Observed actions include credential dumping, local account and group enumeration, attempted Zerologon-based privilege escalation, remote execution and file movement using PsExec, process injection, disabling Microsoft Defender, lateral movement, data theft, and deployment of Cuba ransomware for encryption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
29 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 malware families attributed to this actor across reporting.
5 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Next the threat actors attempted to use a file called zero.exe, which is used to exploit the Zerologon vulnerability to escalate privileges.
We observed the execution of the ProxyLogon exploit. Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
48 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Elastic’s internal activity cluster label for the operator(s) observed in these intrusions; associated in this report with Cuba ransomware operations including Exchange exploitation, persistence via hidden user creation, and post-exploitation tooling deployment.
Activity cluster observed compromising public-facing Exchange servers, establishing hidden-account/RDP persistence, deploying remote-access and post-exploitation tooling, harvesting credentials, moving laterally, and supporting Cuba ransomware intrusions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.