Cuba Ransomware is a financially motivated ransomware and extortion group known for targeting organizations in North America and Europe, particularly retailers, manufacturers, and other enterprises with valuable operational data. The actor has conducted intrusions involving data theft followed by ransomware deployment and extortion, including public leak pressure consistent with double-extortion operations. Reported victimology and revenue estimates place Cuba among the more significant ransomware threats active in the early 2020s. The group’s operations have been associated with exploitation of public-facing services, including Microsoft Exchange and Veeam Backup & Replication vulnerabilities, as well as follow-on activity from malware delivery chains involving Hancitor and Cobalt Strike. Post-compromise tradecraft includes creation of hidden local administrator-capable accounts, enabling remote access, credential theft with tools such as Mimikatz and Meterpreter, privilege-escalation attempts including Zerologon exploitation, and lateral movement with utilities such as PsExec. Cuba operators have also used remote administration tools and proxy/backdoor malware including NetSupport Manager, GoToAssist, SystemBC, and BUGHATCH to maintain access and stage later actions. A notable characteristic of Cuba intrusions is aggressive defense evasion. The group has repeatedly been linked to bring-your-own-vulnerable-driver activity and to signed malicious driver toolchains such as POORTRY, also referred to as BURNTCIGAR, with loaders including STONESTOP. These components have been used to terminate protected security processes, impair or disable endpoint defenses, patch kernel callbacks, and in newer variants delete critical EDR components from disk. Cuba malware and associated tooling have also been observed using masquerading and artifact deletion to reduce forensic visibility, including deletion of dropped components and use of filenames or packaging intended to resemble legitimate software. Aliases include Cuba, Cuba ransomware, Cuba ransomware actors, and Cuba ransomware gang. The actor has also been linked in reporting to UNC2596-associated tooling. While Cuba is primarily documented as a ransomware and extortion operation, some reporting has suggested possible espionage-related activity or a pivot in motivation in certain campaigns; that aspect is not sufficiently consistent to outweigh the group’s dominant criminal extortion profile.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
Next the threat actors attempted to use a file called zero.exe, which is used to exploit the Zerologon vulnerability to escalate privileges.
We observed the execution of the ProxyLogon exploit. Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
Previous research has observed this threat group leveraging ProxyLogon and ProxyShell vulnerabilities to gain initial access.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with ransomware intrusions that used a vulnerable signed driver (aswArPot.sys) as part of BYOVD tradecraft to gain kernel-level capability and disable or tamper with security protections before payload deployment.
Linked to attacks exploiting Veeam Backup & Replication vulnerabilities.
Ransomware gang linked to attacks targeting Veeam Backup & Replication security flaws.
Referenced as a threat actor previously documented using BYOVD techniques in campaigns.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.