Cuba ransomware is a Windows ransomware family used in financially motivated, enterprise-focused attacks since at least 2019. It encrypts local volumes and enterprise network shares using ChaCha20, with RSA protecting the per-file encryption keys and initialization vectors. Operators use double extortion, stealing sensitive information before encryption and threatening publication through a data-leak site. Victims include retailers and manufacturers in North America and Europe, as well as organizations worldwide in financial services, government, healthcare, information technology, and critical manufacturing.
The ransomware supports operator-selected encryption of local volumes, individual paths, discovered network shares, or shares on a specified host. It retrieves the local ARP table and enumerates network shares using Windows APIs. It enables SeDebugPrivilege and terminates selected database, virtualization, email, and other processes and services to release files for encryption. Encryption is multithreaded, and larger files are encrypted intermittently to accelerate execution. Cuba excludes designated system directories and file types, checks for an existing encryption marker to prevent repeat encryption, and can delete its executable after completing encryption. Analyzed variants avoid encryption on systems configured with Russian keyboard layouts. Obfuscated PowerShell deployment, hidden execution windows, and masquerading as legitimate security or VPN software have also been observed.
Cuba campaigns have used phishing, targeted phishing, malvertising, compromised credentials, remote access services, and exploitation of public-facing applications. Hancitor has distributed the ransomware, while associated intrusions have used BUGHATCH, Cobalt Strike, Meterpreter, and other tools for intrusion preparation. Operators have exploited Microsoft Exchange vulnerabilities and CVE-2023-27532 in Veeam Backup & Replication. Deployment activity has been tracked as REF9019 and DEV-0671, and RomCom-associated actors have also deployed Cuba. Credential theft, privilege escalation, lateral movement, security-tool disabling, and data exfiltration occur within these broader operations and are not necessarily native ransomware functions. No affiliation with the Republic of Cuba has been established.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Used a tool to exploit CVE-2020-1472 (also known as “ZeroLogon”) to gain Domain Administrative privileges. This tool and its intrusion attempts have been reportedly related to Hancitor and Qbot.
Microsoft says Cuba ransomware threat actors are hacking Microsoft Exchange servers unpatched against a critical server-side request forgery vulnerability also exploited in Play ransomware attacks. Rackspace confirmed that Play ransomware used an exploit dubbed OWASSRF targeting CVE-2022-41080 after bypassing ProxyNotShell URL rewrite mitigations.
Cuba ransomware actors have exploited CVE-2022-24521 in the Windows Common Log File System (CLFS) driver to steal system tokens and elevate privileges.
The Cuba Ransomware group targets North American and European retailers and manufacturers, exfiltrating sensitive data before deploying ransomware and using a "name and shame" extortion model.
The Cuba Ransomware group targets North American and European retailers and manufacturers, exfiltrating sensitive data before deploying ransomware and using a "name and shame" extortion model.
Following the publication of a report regarding the Cuba ransomware group’s recent activities, the STRIKE Team leveraged SecurityScorecard’s unique data to enrich the indicators of compromise linked to this activity.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
"The most severe of the problems addressed is CVE-2024-40711, a critical (CVSS v3.1 score: 9.8) remote code execution (RCE) vulnerability on Veeam Backup & Replication (VBR) that can be exploited without authentication."
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“Initially, the group was associated with deploying the Cuba ransomware through methods like malvertising and targeted phishing operations.”
Redmond says that this SSRF vulnerability has also been exploited since at least November 17th by another threat group it tracks as DEV-0671 to hack Exchange servers and deploy Cuba ransomware payloads.
Redmond says that this SSRF vulnerability has also been exploited since at least November 17th by another threat group it tracks as DEV-0671 to hack Exchange servers and deploy Cuba ransomware payloads.
The Cuba Ransomware group targets North American and European retailers and manufacturers, exfiltrating sensitive data before deploying ransomware and using a "name and shame" extortion model.
CUBA ransomware provides the attacker with the flexibility to encrypt both local and network shares files in the enterprise. CUBA uses the ChaCha20 cipher algorithm for symmetric encryption and RSA encryption to protect the ChaCha20 keys.
"Their ransomware arsenal evolved over time: Cuba ransomware (early 2020)..."
24 distinct techniques documented for this family, organized by ATT&CK tactic.
CUBA starts by acquiring SeDebugPrivilege and then terminates a hardcoded list of processes and services.
179 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
78 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware that encrypts files in corporate networks using AES, appends the .cuba extension, drops ransom notes, and demands payment for a private decryption key. The content also states operators claimed to exfiltrate databases, FTP servers, and file servers before extortion.
A named ransomware family mentioned only to clarify that, despite its name, it likely did not originate from Cuba.
Ransomware that executes PowerShell in hidden windows for stealth.
A ransomware family/group active since 2019. In this reference it is discussed as the operator associated with BUGHATCH infrastructure and as exploiting CVE-2023-27532 against Veeam Backup & Replication to pressure victims by compromising backup and recovery options.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.