Wedgecut is a Windows-based reconnaissance utility associated with Cuba ransomware operations, tracked by Mandiant under UNC2596. It is used during post-compromise discovery to enumerate Active Directory environments through PowerShell and to identify active hosts on victim networks, including by issuing ICMP ping requests against generated host lists. The tool has commonly been observed under the name check.exe and is part of a broader intrusion toolkit that has included BUGHATCH, BURNTCIGAR, TERMITE, Cobalt Strike, and NetSupport. Wedgecut has been deployed in intrusions following exploitation of public-facing Microsoft Exchange vulnerabilities such as ProxyShell and ProxyLogon, after the operators established footholds with web shells, backdoors, or remote access tooling. Its role is to support internal network mapping and target selection ahead of lateral movement, data theft, and ransomware deployment. Activity involving Wedgecut has been observed in campaigns affecting organizations in the United States and Canada, including critical infrastructure victims targeted by the Cuba ransomware ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Wedgecut comes in the form of an executable named “check.exe,” which is a reconnaissance tool that enumerates the Active Directory through PowerShell.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Enumeration tool used for network reconnaissance by Cuba ransomware group.
Reconnaissance tool used by the Cuba actors to enumerate Active Directory via PowerShell.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.