White Baku is the threat actor associated with Cuba ransomware, a financially motivated cybercriminal operation. The actor has been observed gaining initial access by exploiting ProxyShell vulnerabilities in Microsoft Exchange to deploy web shells. Post-compromise activity has included use of Cobalt Strike along with tooling such as Mozzy and RDP Facilitator to support persistence and lateral movement within victim environments. The group is part of the broader ransomware ecosystem and is known for intrusion activity consistent with enterprise ransomware operations, including exploitation of public-facing systems followed by internal expansion and hands-on post-exploitation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.