Cuba is ransomware associated with an organized, financially motivated extortion group tracked as Cuba Ransomware. It has been active since at least December 2020 and is known to encrypt system data and append the .cuba extension to encrypted files. The group uses double-extortion and a "name and shame" model, exfiltrating sensitive data and threatening publication to pressure victims into paying. Reported targeting includes small and medium-sized retailers as well as North American and European retailers and manufacturers.
Observed tradecraft in the provided content includes checking whether Russian language is installed on an infected machine via GetKeyboardLayoutList, querying service status with QueryServiceStatusEx, and modifying services using OpenService and ChangeServiceConfig. Cuba has executed hidden PowerShell windows, has been dropped onto systems and used for lateral movement via obfuscated PowerShell scripts, and has loaded payloads into memory using PowerShell. It can use cmd.exe /c del to delete artifacts from the system. The malware also has keylogging capability via GetKeyState and VkKeyScan, and has used SeDebugPrivilege with AdjustTokenPrivileges to elevate privileges.
The content also states that Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs, and that packed payloads have been observed when it is delivered. Elastic reported activity linked to the Cuba ransomware ecosystem involving exploitation of Microsoft Exchange servers, use of Meterpreter, SystemBC, GoToAssist, NetSupport Manager, Cobalt Strike, BUGHATCH, Mimikatz, PsExec, and DefenderControl prior to ransomware deployment, though those tools are associated with the intrusion set rather than necessarily the ransomware binary itself. Additional reporting in the content links Cuba-related operations to BURNTCIGAR, a loader/driver combination used in attempts to disable endpoint security tools before ransomware deployment, and notes prior exploitation of Veeam Backup & Replication vulnerabilities by actors associated with the Cuba ransomware gang. The content also notes assessments that, despite the name, Cuba Ransomware likely did not originate from Cuba, and Microsoft reported the intrusion set as opportunistic and lucrative-oriented, with some espionage-related motivations also assessed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Elastic Security Team is tracking an organized and financially-motivated ransomware and extortion group called Cuba Ransomware... deploying ransomware... uses a “name and shame” approach
Elastic Security Team is tracking an organized and financially-motivated ransomware and extortion group called Cuba Ransomware... deploying ransomware... uses a “name and shame” approach
"The most severe of the problems addressed is CVE-2024-40711, a critical (CVSS v3.1 score: 9.8) remote code execution (RCE) vulnerability on Veeam Backup & Replication (VBR) that can be exploited without authentication."
Next the threat actors attempted to use a file called zero.exe, which is used to exploit the Zerologon vulnerability to escalate privileges.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Prior research indicate that threat actors who used this tool in prior attacks later attempted to deploy ransomware that calls itself Cuba. ... Our incident and the incident from PAN’s report are both linked to Cuba ransomware, with high confidence.
Elastic Security Team is tracking an organized and financially-motivated ransomware and extortion group called Cuba Ransomware... deploying ransomware... uses a “name and shame” approach
"Their ransomware arsenal evolved over time: Cuba ransomware (early 2020)..."
24 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions. | APT1 has used the Windows command shell to execute commands, and batch scripting to automate execution. Blue Mockingbird has used batch script files to automate execution and deployment of payloads. During HomeLand Justice, threat actors used Windows batch files for persistence and execution.
“Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer… replaced the ImagePath registry value of a Windows service with a new backdoor binary… [multiple groups/malware] creating a service / installing as a service / modifying service configurations for persistence.”
“Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer… replaced the ImagePath registry value of a Windows service with a new backdoor binary… [multiple groups/malware] creating a service / installing as a service / modifying service configurations for persistence.”
The content repeatedly describes malware and threat actors using obfuscated code, encrypted strings, Base64/XOR/RC4/AES encoding, VMProtect/ConfuserEx/SmartAssembly, stack strings, control-flow flattening, opaque predicates, and hidden payloads to evade analysis and detection.
"Sandworm Team used UPX to pack a copy of Mimikatz"; "APT38 has used several code packing methods such as Themida, Enigma, VMProtect, and Obsidium"; "Lazarus Group packed malicious .db files with Themida to evade detection."
During the 2016 Ukraine Electric Power Attack, DLLs and EXEs with filenames associated with common electric power sector protocols were used to masquerade files.
Bad Rabbit has masqueraded as a Flash Player installer through the executable file install_flash_player.exe.
Examples throughout the content include deleting tools, logs, malware-related files, staged archives, screenshots, temporary files, and exfiltrated data 'to cover their tracks,' 'reduce their footprint,' 'remove traces of activity,' or as part of 'post-intrusion cleanup.'
The content repeatedly describes threat actors and malware deleting files, tools, scripts, logs, droppers, staged data, and artifacts from compromised systems to cover tracks, remove evidence, or self-delete.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden. APT28 has used the WindowStyle parameter to conceal PowerShell windows.
They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.
"Brute Ratel C4 has used reflective loading to execute malicious DLLs." / "Cobalt Strike's execute-assembly command can run a .NET executable within the memory of a sacrificial process..." / "FoggyWeb's loader has reflectively loaded .NET-based assembly/payloads into memory."
"actors used the following command ... to obtain information about services: net start"; "APT1 used the commands net start and tasklist to get a listing of the services on the system"; "OilRig has used sc query on a victim to gather information about services"; "Indrik Spider has used the win32_service WMI class to retrieve a list of services"
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
Multiple entries describe enumerating local, logical, or physical drives and disk/volume information, e.g., 'can enumerate local drives,' 'GetLogicalDrives,' 'fsutil fsinfo drives,' 'list drives,' and 'discover logical drive information including the drive type, free space, and volume information.'
"Babuk can enumerate disk volumes, get disk information"; "Ryuk has called GetLogicalDrives ... and GetDriveTypeW"; "Cuba can enumerate local drives, disk type, and disk free space"; "Chimera ... fsutil fsinfo drives"
"Emotet ... WNetEnumResourceW to enumerate non-hidden shares"; "Cuba ... discovery like GetIpNetTable and NetShareEnum"; "Clop ... WNetOpenEnumW(), WNetEnumResourceW()"
Avaddon checks for specific keyboard layouts and OS languages to avoid targeting Commonwealth of Independent States (CIS) entities... Bazar can perform a check to ensure that the operating system's keyboard and language settings are not set to Russian... Clop has checked the keyboard language using the GetKeyboardLayout() function... Ryuk has been observed to query the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Nls\Language and the value InstallLanguage.
"During the 2022 Ukraine Electric Power Attack, Sandworm Team utilized a PowerShell utility called TANKTRAP to spread and launch a wiper using Windows Group Policy," and "Cuba has been dropped onto systems and used for lateral movement via obfuscated PowerShell scripts."
29 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named ransomware family mentioned only to clarify that, despite its name, it likely did not originate from Cuba.
Ransomware family/gang linked to attacks targeting Veeam Backup & Replication (VBR) vulnerabilities.
A ransomware family associated with RomCom operations via shared infrastructure/payload delivery and used for double-extortion attacks.
Ransomware linked (via its operators) to exploitation of Veeam Backup & Replication vulnerabilities for attack operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.