Cuba Ransomware, also tracked in some reporting as REF9019, is a financially motivated cybercriminal threat actor conducting ransomware and data-theft extortion operations. The group has targeted small and medium-sized organizations, with observed emphasis on retailers and manufacturers in North America and Europe. Its operations combine theft of sensitive data with ransomware deployment and public leak pressure, consistent with double-extortion activity. Observed intrusion activity has been linked to compromises of public-facing Microsoft Exchange servers, including exploitation associated with ProxyLogon and ProxyShell. After access, the actor establishes persistence by creating a hidden local administrative user and enabling Remote Desktop access. Post-compromise tradecraft includes use of SystemBC, legitimate remote administration tools such as GoToAssist and NetSupport Manager, Cobalt Strike beacons, and the BUGHATCH downloader. Credential access has included Meterpreter-based harvesting and Mimikatz. Privilege escalation activity has included attempted exploitation of Zerologon, while lateral movement has involved PsExec and other living-off-the-land techniques. Defense evasion has included disabling Microsoft Defender and maintaining that state through scheduled task abuse. The actor also uses process injection during post-exploitation. Cuba Ransomware is associated with organized criminal ransomware operations rather than a nation-state espionage mission.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Next the threat actors attempted to use a file called zero.exe, which is used to exploit the Zerologon vulnerability to escalate privileges.
We observed the execution of the ProxyLogon exploit. Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
48 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.