Trend Micro reported renewed activity by the Cuba ransomware group and identified a new variant that refined both intrusion and encryption behavior. The malware used BUGHATCH, a custom downloader, during staging and appeared modified to improve execution reliability while reducing unintended system impact. Researchers said the variant expanded the list of terminated processes and services before encryption, including SQL, virtualization platforms, Outlook, and Microsoft Exchange components, while also widening its safelist of directories and file extensions to avoid encrypting files that could disrupt operations or the attack itself.
A later sample observed against two organizations in Asia showed the group sharpening its extortion playbook. The revised ransom note explicitly threatened to publish exfiltrated data after three days if victims did not engage, and it added qTox/quTox contact details to support negotiations. Trend Micro said the same onion site appeared across ransom notes, linking the incidents to the same operation and indicating that Cuba’s ransomware campaign remained active and evolving.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Trend Micro said detections of new Cuba ransomware samples in May 2022 suggested the group's attacks would continue in the coming months.
Trend Micro said the latest variant's ransom note added qTox/quTox contact details as a technical support channel to facilitate ransom payment negotiations.
The late-April 2022 variant used a revised ransom note that threatened to publish exfiltrated data on the group's Tor site after three days if victims did not negotiate, indicating double extortion.
Trend Micro observed another Cuba ransomware variant in late April 2022 targeting two organizations in Asia.
Samples examined from March and April 2022 used the custom downloader BUGHATCH during the staging phase, a technique Trend Micro said previous Cuba variants had not used.
Trend Micro reported a resurgence of Cuba ransomware activity during March and April 2022 and analyzed samples from that period.
The report cited an FBI official notice stating that Cuba ransomware resurfaced in November 2021.
Trend Micro said the Cuba ransomware malware family was first observed in February 2020.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.