Threat actors used unpatched Microsoft Exchange servers as an initial access point to deploy both Babuk and Cuba ransomware, with campaigns heavily affecting organizations in the United States and additional victims in other countries. Cisco Talos reported that a newer actor it tracks as Tortilla likely exploited ProxyShell to compromise Exchange, install the China Chopper web shell, stage payloads with PowerShell, and ultimately launch Babuk ransomware that appended the .babyk extension after disabling backup-related services and deleting VSS snapshots.
A separate intrusion set tied to Cuba ransomware also abused Exchange flaws, including ProxyShell and ProxyLogon, to breach corporate networks and deploy ransomware at scale. Mandiant said the actors, tracked as UNC2596 and associated with COLDDRAW, combined public Exchange exploitation with tools such as Bughatch, Wedgecut, Burntcigar, and Termite to maintain persistence, escalate privileges, move laterally, and disable defenses; the activity followed earlier FBI reporting that Cuba had compromised dozens of U.S. critical infrastructure organizations, underscoring the continued risk from internet-exposed, unpatched Exchange servers.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
In December 2021, the FBI issued a Cuba ransomware advisory warning that the group had breached 49 critical infrastructure organizations in the United States.
On October 12, 2021, Cisco Talos discovered a campaign in which Tortilla exploited vulnerable Microsoft Exchange servers, likely via ProxyShell, and deployed Babuk ransomware. The campaign primarily hit organizations in the United States, with additional victims in the United Kingdom, Germany, Ukraine, Finland, Brazil, Honduras, and Thailand.
GuidePoint later assessed with high confidence that a September 2021 'Ransomware Near Miss' it had investigated was attributable to the Cuba ransomware group (UNC2596). The incident began with ProxyShell exploitation and involved Cobalt Strike, Agent32.bin, and komar.ps1, but ransomware deployment was prevented.
Talos said the Babuk source code and a builder leaked in September 2021, likely enabling less experienced operators such as Tortilla to deploy the ransomware.
Mandiant identified UNC2596 exploiting Microsoft Exchange vulnerabilities, including ProxyShell and ProxyLogon, as early as August 2021 to gain initial access and deploy web shells, RATs, and backdoors.
Cisco Talos said the threat actor it tracks as Tortilla had been active since July 2021 and initially experimented with payloads including Powercat before deploying Babuk ransomware.
In May 2021, Cuba worked with Hancitor spam operators to gain initial access through DocuSign-themed phishing emails before later shifting toward exploiting public-facing services.
ProxyShell, an Exchange Server exploit chain, was demonstrated at Pwn2Own 2021. The chain was described as allowing an unauthenticated attacker to execute arbitrary commands on Exchange servers with port 443 exposed.
Mandiant reported that Cuba ransomware activity grew during 2020 and 2021 as the operation expanded its intrusions and ransomware deployments.
The Cuba ransomware operation began at the end of 2019, marking the start of the activity later tracked by Mandiant as UNC2596 and its payload as COLDDRAW.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 29 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourceguidepointsecurity.com
Open sourceblog.talosintelligence.com
Open sourceblog.orange.tw
Open sourcezerodayinitiative.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.