Skip to content

Cuba

Cuba Ransomware is a financially motivated ransomware and extortion operation active since at least 2019 that has targeted organizations in North America and Europe, including retailers, manufacturers, and other enterprises.

Profile source: Mallory opens in a new tab

Cuba

Family profile

Cuba Ransomware is a financially motivated ransomware and extortion operation active since at least 2019 that has targeted organizations in North America and Europe, including retailers, manufacturers, and other enterprises. The group is known for combining data theft with ransomware deployment and using leak-site pressure to extort victims. Cuba has also been linked to attacks against backup and recovery infrastructure, including exploitation of Veeam Backup & Replication vulnerabilities, reflecting an interest in disrupting restoration and increasing leverage over victims.

The operation commonly relies on a multi-stage intrusion chain using commodity and dual-use tooling. Reported tooling associated with Cuba intrusions includes Cobalt Strike, SystemBC, Meterpreter, Mimikatz, PsExec, PowerShell-based loaders, and legitimate remote administration software such as GoToAssist and NetSupport Manager. Cuba activity has also been associated with BUGHATCH and with malware delivery ecosystems such as Hancitor, which in some cases delivered Cobalt Strike followed by Cuba ransomware. The group has used loaders and in-memory execution techniques, including PowerShell-based payload loading, to reduce on-disk visibility.

Cuba’s tradecraft includes exploitation of public-facing services, credential theft, privilege escalation, lateral movement, and defense evasion prior to encryption. Observed behaviors include enabling remote access, creating hidden local accounts, abusing LOLBAS utilities, and deleting artifacts to hinder forensic recovery. Cuba operators have also used masquerading techniques, including disguising malware as legitimate security or VPN software.

A notable aspect of the group’s capability is its use of Bring Your Own Vulnerable Driver techniques to disable security products. Cuba has been linked to the BURNTCIGAR/POORTRY malicious driver family and associated loaders such as STONESTOP, which have been used to terminate or impair endpoint protection and EDR tooling. Reporting has tied Cuba to the broader ecosystem of ransomware actors using signed vulnerable or malicious kernel drivers for defense evasion.

Cuba is generally tracked as a cybercriminal ransomware actor rather than a confirmed state-sponsored intrusion set. However, some reporting has noted activity associated with the Cuba intrusion set that appeared espionage-related, including phishing campaigns affecting defense and government entities in Europe and North America. That overlap has led to some uncertainty around whether all activity attributed to Cuba reflects a single purely financially motivated cluster, a mixed-motive intrusion set, or partially overlapping operators. High-confidence reporting consistently supports Cuba’s role as a ransomware and extortion actor.

Known aliases include Cuba, Cuba ransomware, Cuba ransomware actors, and Cuba ransomware gang.

Operational record

1
YARA rules
1
Ransom notes
2
Leak sites
0 available

Credential Theft

  • Mimikatz

Defense Evasion

  • Avast Anti-Rootkit driver

LOLBAS

  • PsExec

Networking

  • Termite

Offsec

  • Cobalt Strike
  • Meterpreter

RMM Tools

  • NetSupport

MITRE ATT&CK

Cuba in ATT&CK

65 distinct techniques

Techniques

65 techniques
T1068 Exploitation for Privilege Escalation T1090 Proxy T1071 Application Layer Protocol T1485 Data Destruction T1203 Exploitation for Client Execution T1190 Exploit Public-Facing Application T1486 Data Encrypted for Impact T1553.002 Code Signing T1027.002 Software Packing T1014 Rootkit T1543.003 Windows Service T1562 Impair Defenses T1546.015 Component Object Model Hijacking T1021.004 SSH T1041 Exfiltration Over C2 Channel T1055 Process Injection T1059.001 PowerShell T1222 File and Directory Permissions Modification T1566.001 Spearphishing Attachment T1018 Remote System Discovery T1620 Reflective Code Loading T1136.001 Local Account T1564 Hide Artifacts T1059.003 Windows Command Shell T1547.001 Registry Run Keys / Startup Folder T1105 Ingress Tool Transfer T1482 Domain Trust Discovery T1053.005 Scheduled Task T1021.002 SMB/Windows Admin Shares T1021.001 Remote Desktop Protocol T1003 OS Credential Dumping T1219 Remote Access Tools T1005 Data from Local System T1497 Virtualization/Sandbox Evasion T1016 System Network Configuration Discovery T1566.002 Spearphishing Link T1562.001 Disable or Modify Tools T1083 File and Directory Discovery T1082 System Information Discovery T1573 Encrypted Channel T1560 Archive Collected Data T1074 Data Staged T1490 Inhibit System Recovery T1555 Credentials from Password Stores T1572 Protocol Tunneling T1566 Phishing T1036 Masquerading T1560.001 Archive via Utility T1568 Dynamic Resolution T1078.003 Valid Accounts: Local Accounts T1133 External Remote Services T1106 Native API T1204.002 User Execution: Malicious File T1569.002 System Services: Service Execution T1036.005 Masquerading: Match Legitimate Name or Location T1212 Exploitation for Credential Access T1016.001 Network Configuration Discovery: Network Connection Enumeration T1057 Process Discovery T1124 Time Discovery T1135 Network Share Discovery T1333 External Remote Services T1570 Tool Transfer T1071.001 Application Layer Protocol: Web Protocols T1071.004 Application Layer Protocol: DNS T1090.003 Multi-hop Proxy

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.