Cuba ransomware is a financially motivated ransomware operation active since 2019, also tracked as UNC2596 and REF9019; Mandiant has used the name COLDDRAW for its ransomware payload. The group has primarily targeted organizations in the United States and Canada, including U.S. critical-infrastructure entities in government, financial services, health care, information technology, and manufacturing. It has also targeted retailers and manufacturers in Europe and organizations in Asia. Cuba conducts human-operated, double-extortion intrusions. Operators have obtained access by exploiting public-facing Microsoft Exchange vulnerabilities including ProxyLogon and ProxyShell, exploiting Veeam Backup & Replication CVE-2023-27532, phishing, abuse of misconfigured internet-facing systems, and use of initial-access brokers. Post-compromise activity includes deployment of web shells and remote-access tooling; credential theft with Mimikatz and related tools; Active Directory and host reconnaissance; lateral movement through RDP, SMB, PsExec, and Cobalt Strike; and disabling endpoint protections. Cuba has used custom malware including BUGHATCH, Wedgecut, and BurntCigar, alongside commodity tooling such as Cobalt Strike, Meterpreter, NetSupport Manager, and SystemBC. BUGHATCH is a custom in-memory command-and-control implant used in Cuba campaigns. It supports host profiling, encrypted HTTP(S) communications, command and PowerShell execution, reflective payload loading, process injection, token impersonation, agent deployment, and command-and-control migration. Cuba has also employed bring-your-own-vulnerable-driver techniques, including BurntCigar/PoorTry-related tooling, to terminate or disable security products at kernel level before exfiltration and encryption. The ransomware encrypts local volumes and network shares, terminates database, virtualization, email, and other file-locking services, and avoids execution on systems configured with Russian keyboard layouts. It uses hybrid ChaCha20 and RSA cryptography and supports intermittent encryption for larger files. Cuba exfiltrates data before encryption and operates a leak site to pressure victims that decline payment or negotiation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
We observed the execution of the ProxyLogon exploit. Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
Next the threat actors attempted to use a file called zero.exe, which is used to exploit the Zerologon vulnerability to escalate privileges. This file is executed on a vulnerable domain controller to dump the NTLM hash for the Administrator.
52 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with ransomware intrusions that used a vulnerable signed driver (aswArPot.sys) as part of BYOVD tradecraft to gain kernel-level capability and disable or tamper with security protections before payload deployment.
Linked to attacks exploiting Veeam Backup & Replication vulnerabilities.
Ransomware gang linked to attacks targeting Veeam Backup & Replication security flaws.
A technically sophisticated ransomware and extortion group, suspected of emerging from Russia, that targets major financial corporations and uses BYOVD techniques, server exploits, initial-access brokers, lateral movement, data exfiltration, and money laundering infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.