BUGHATCH is a custom Windows command-and-control implant and backdoor associated with Cuba ransomware operations, which Mandiant tracks as UNC2596. First observed in Cuba campaigns during February 2022, it is used for staging, payload delivery, host profiling, and operator-directed execution before ransomware deployment and data-extortion activity. It has been deployed through the memory-only TERMITE PowerShell dropper, which retrieves shellcode and an encrypted implant that is reflectively loaded into memory.
BUGHATCH profiles compromised hosts by collecting system, network-interface, user, token-group, process, and platform information. It communicates with command-and-control infrastructure over HTTP or HTTPS, using a custom protocol and a per-session XOR layer to protect transmitted profiling data and command output. The implant supports execution of command-shell and PowerShell commands, local and remote shellcode, payloads stored on disk, and reflectively loaded PE files and DLLs. It can create suspended processes, inject and execute payloads within them, impersonate or duplicate access tokens, spawn additional agents, terminate processes, migrate command-and-control, and remove itself.
Cuba operators have used BUGHATCH alongside commodity post-exploitation tooling and other bespoke components in intrusions affecting organizations including retailers and manufacturers in North America and Europe. Cuba activity has also targeted critical-infrastructure sectors. Initial compromise in associated operations has commonly involved exploitation of public-facing services, particularly Microsoft Exchange vulnerabilities; BUGHATCH is a post-compromise implant rather than the demonstrated initial-access mechanism.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The report highlighted a novel feature of the Cuba group’s operations, exploitation of CVE-2023-27532, a vulnerability affecting Veeam Backup & Replication software.
We observed the execution of the ProxyLogon exploit. Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"BUGHATCH is the name given to a Cuba Ransomware associated downloader" and Elastic assessed Agent32.bin to be BUGHATCH malware.
"BUGHATCH is the name given to a Cuba Ransomware associated downloader" and Elastic assessed Agent32.bin to be BUGHATCH malware.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
"BUGHATCH was launched via PowerShell script stagers" including agsyst82.ps1 and komar2.ps1, which downloaded Agent32.bin and attempted injection into svchost.exe.
BUGHATCH creates suspended cmd.exe or svchost.exe processes, writes shellcode and encrypted PE payloads into their memory, sets thread context, and resumes execution.
ReflectivelyLoadDllRemote allocates memory with VirtualAllocEx, writes a DLL with WriteProcessMemory, and creates a remote thread using CreateRemoteThread.
ReflectivelyExecutePERemote and Command 3 load PE binaries in the memory space of a created suspended process.
The malware creates a suspended process, sets the suspended thread instruction pointer with SetThreadContext, then calls ResumeThread to execute injected shellcode.
For Command 3, BUGHATCH creates a suspended cmd.exe or svchost.exe process, allocates remote memory, writes a loader and encrypted PE, redirects execution, and resumes the process.
ImpersonateToken ... an attacker can either impersonate the explorer.exe token or create a token from credentials (Domain\Username, Password) sent by the C2 to spawn another instance of the current process.
ImpersonateToken can duplicate the explorer.exe token with DuplicateTokenEx and spawn another instance of the current process with the duplicated token.
The malware calls LogonUserW with C2-supplied Domain\User credentials and password to create a token, then spawns another instance of itself with that token.
The PowerShell loader is obfuscated and stores shellcode in reverse-Base64 format; BUGHATCH XOR-encrypts embedded PE payloads and C2 data.
BUGHATCH creates suspended cmd.exe or svchost.exe processes, writes shellcode and encrypted PE payloads into their memory, sets thread context, and resumes execution.
ReflectivelyLoadDllRemote allocates memory with VirtualAllocEx, writes a DLL with WriteProcessMemory, and creates a remote thread using CreateRemoteThread.
ReflectivelyExecutePERemote and Command 3 load PE binaries in the memory space of a created suspended process.
The malware creates a suspended process, sets the suspended thread instruction pointer with SetThreadContext, then calls ResumeThread to execute injected shellcode.
For Command 3, BUGHATCH creates a suspended cmd.exe or svchost.exe process, allocates remote memory, writes a loader and encrypted PE, redirects execution, and resumes the process.
SelfDeleteExitProcess obtains its current executable path and runs "cmd.exe /c del FILEPATH >> NUL" before exiting.
ImpersonateToken ... an attacker can either impersonate the explorer.exe token or create a token from credentials (Domain\Username, Password) sent by the C2 to spawn another instance of the current process.
ImpersonateToken can duplicate the explorer.exe token with DuplicateTokenEx and spawn another instance of the current process with the duplicated token.
The malware calls LogonUserW with C2-supplied Domain\User credentials and password to create a token, then spawns another instance of itself with that token.
The implant starts by enabling SeDebugPrivilege, allowing it to access and read memory from other processes.
It collects the addresses of network interfaces connected to the infected machine using GetIpAddrTable.
The implant retrieves the username and domain of the current process account with GetTokenInformation and LookupAccountSidW.
the C2 then responds with the operator’s command if available, or else the agent sleeps for 60 seconds ... The main loop is made up of the following: Send POST request ... Sleep for 60 seconds
The implant uses HTTP(S) for communications and sends victim information and command output in HTTP POST requests to the C2 server.
The initial shellcode downloads another shellcode blob and the encrypted PE implant from C2; SpawnAgent32/64 downloads packed agent shellcode from /Agent32.bin or /Agent64.bin.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom malware strain used by the Cuba ransomware group for command-and-control. The report links BUGHATCH to infrastructure that served malware downloads and to certificate-based infrastructure clustering associated with Cuba activity.
Downloader malware used by Cuba ransomware group to fetch additional payloads during attacks.
Bughatch is a custom backdoor used by the Cuba ransomware group. It is deployed in process memory, connects to a C2 server, collects system and network information, and can download and execute additional payloads such as Cobalt Strike Beacon or Metasploit modules.
Named as associated malware in the broader CUBA campaign, but no functional details are provided in this reference.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.