Cuba Ransomware

Malware Profile Updated 3 months ago
Download STIX
Preview STIX
The Cuba ransomware is a malicious software that first appeared on cybersecurity radars in late 2020 under the name "Tropical Scorpius." It is designed to exploit and damage computer systems, often infiltrating through suspicious downloads, emails, or websites without the user's knowledge. Once inside a system, it can steal personal information, disrupt operations, or hold data hostage for ransom. The FBI identified various tactics, techniques, and procedures (TTPs) used by Cuba ransomware actors as of August 2022. However, the exact threat group behind this malware remains unconfirmed, though similarities were observed with the TTPs of the Cuba Ransomware group around that time. In one notable incident, the Cuba ransomware gang claimed responsibility for an attack on Etron Technology, a company based in Taiwan. The stolen data included financial documents and tax information. This cybercriminal group has no relation to the country of Cuba. In another instance, they exploited a bug to target critical infrastructure organizations in the United States and IT firms in Latin America. The group has also been linked to a significant remote code execution (RCE) flaw in Windows Search, tracked as CVE-2023-36884, using geopolitical events such as the Ukrainian World Congress and July 2023 NATO summit as lures. Void Rabisu, another cyber threat group, has been associated with deploying Cuba ransomware, possibly exclusively. They use a mix of TTPs common to both cybercriminals and nation state-sponsored hackers. The group was detected exploiting the aforementioned RCE flaw in June, indicating a shift among some financial-seeking threat actors towards campaigns motivated by espionage due to extraordinary geopolitical circumstances, particularly the war in Ukraine.
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Tropical Scorpius
3
Tropical Scorpius is a notorious malware, first identified in late 2020, associated with the Cuba ransomware gang. This malicious software has been linked to multiple cybercriminal activities, including disrupting operations, stealing personal information, and holding data hostage for ransom. The ma
Void Rabisu
2
Void Rabisu, also known as Storm-0978, UNC2596, and Tropical Scorpius, is a malicious software (malware) notable for its use of the ROMCOM backdoor. This malware has been involved in numerous attacks, including those targeting attendees of the Women Political Leaders Summit (WPL Summit) in 2023. In
Colddraw
1
Colddraw, also known as Cuba and Fidel ransomware, first emerged on the cybersecurity threat landscape in 2019. This malicious software has been strategically targeting a moderate pool of victims over the years, marking encrypted files for the ransomware's and its decryptor's identification. The mal
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Ransomware
Exploit
Malware
Extortion
Vulnerability
Data Leak
Zero Day
Remote Code ...
State Sponso...
Espionage
Loader
Fbi
Antivirus
RCE (Remote ...
Windows
Encryption
Phishing
Ransom
Lateral Move...
Exploits
Credentials
Mysql
Ukraine
Outlook
CISA
Gbhackers
Blackberry
Veeam
Kaspersky
Downloader
Cybercrime
Apt
Backdoor
Rat
Associated Malware
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
CubaUnspecified
4
The Cuba ransomware, a malicious software active since 2019, has been linked to a series of escalating attacks on US entities and European leaders. The criminal group behind the malware, known by various aliases such as Void Rabisu, UNC2596, Tropical Scorpius, and Storm-0978, has recently targeted w
RomComUnspecified
3
RomCom is a type of malware, specifically a Remote Access Trojan (RAT), that has been linked to several cyber-attacks across Europe and North America. It was first identified in spring 2022, when third-party and open-source reports highlighted a potential connection between Cuba ransomware actors, R
Romcom RatUnspecified
3
RomCom RAT, a type of malware, has been linked to Cuba ransomware and Industrial Spy ransomware actors since spring 2022. These malicious actors have been observed deploying the RomCom RAT and Meterpreter Reverse Shell HTTP/HTTPS proxy via a Command and Control (C2) server before initiating their ra
AvosLockerUnspecified
2
AvosLocker is a type of malware, specifically a ransomware, that has been causing significant issues across the digital landscape. Ransomware is a form of malicious software designed to exploit and damage computer systems, often infiltrating through suspicious downloads, emails, or websites without
LockbitUnspecified
1
LockBit is a type of malware, specifically ransomware, that infiltrates systems to exploit and damage them. It can enter your system through various channels such as suspicious downloads, emails, or websites, often without the user's knowledge. Once inside, it can steal personal information, disrupt
Lv RansomwareUnspecified
1
LV Ransomware is a type of malicious software designed to exploit and damage computer systems, often infiltrating systems through suspicious downloads, emails, or websites. This ransomware variant, also known as ".0nzo8yk Virus," was first identified in the wild in June 2020 and is a modified versio
HancitorUnspecified
1
Hancitor is a malicious software (malware) known for its ability to exploit and damage computer systems. It can infiltrate systems through suspicious downloads, emails, or websites, often unbeknownst to the user. Once it gains access, Hancitor can steal personal information, disrupt operations, or e
Cobalt Strike BeaconUnspecified
1
Cobalt Strike Beacon is a type of malware known for its harmful capabilities, including stealing personal information, disrupting operations, and potentially holding data hostage for ransom. The malware has been loaded by HUI Loader through various files such as mpc.tmp, dlp.ini, vmtools.ini, and an
Romcom BackdoorUnspecified
1
The RomCom backdoor, a malicious software, is primarily used by the threat actor Void Rabisu, also known as Tropical Scorpius or Storm-0978. This malware has been associated with Cuba ransomware and has been notably deployed in cyberespionage activities, shifting away from opportunistic ransomware a
Romcom Remote Access TrojanUnspecified
1
The RomCom Remote Access Trojan (RAT) is a type of malware that has gained significant attention in the cybersecurity landscape this year. This malicious software, designed to exploit and damage computer systems, can infiltrate systems via suspicious downloads, emails, or websites, often unbeknownst
Associated Threat Actors
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
LapsusUnspecified
1
Lapsus is a significant threat actor that has been active since its inception in early 2022. The group gained notoriety for its cyberattacks, including a high-profile breach of Nvidia, an American multinational technology company, in the same year. This attack led to the leak of thousands of passwor
Unc2596Unspecified
1
UNC2596, also known as Void Rabisu, Tropical Scorpius, and Storm-0978, is a hybrid threat actor involved in both financially motivated and espionage attacks. This group has been refining its tactics and techniques, utilizing backdoor attacks that have targeted various high-profile events, including
Associated Vulnerabilities
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
ZerologonUnspecified
2
Zerologon is a critical vulnerability (CVE-2020-1472) found within Microsoft's Netlogon Remote Protocol, impacting all versions of Windows Server OS from 2008 onwards. This flaw in software design or implementation allows attackers to bypass authentication mechanisms and change computer passwords wi
CVE-2023-27532Unspecified
1
CVE-2023-27532 is a high-severity vulnerability discovered in Veeam's Backup & Replication software. This flaw, disclosed in March 2023, can be exploited to breach backup infrastructure hosts. Despite its serious implications, it was not added to the Known Exploited Vulnerabilities (KEV) list until
CVE-2023-36884Unspecified
1
CVE-2023-36884 is a significant software vulnerability discovered in Microsoft Windows, Server, Office, and Outlook. It is a flaw in the software design or implementation that allows for remote code execution (RCE), specifically in the Windows Search security feature. This vulnerability was being ac
CVE-2020-1472Unspecified
1
CVE-2020-1472, also known as the ZeroLogon vulnerability, is a critical-severity privilege escalation flaw in Microsoft's Netlogon Remote Protocol. It was patched by Microsoft on August 11, 2020. This vulnerability allows attackers to gain administrative access to a Windows domain controller without
Source Document References
Information about the Cuba Ransomware Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
SourceCreatedAtTitle
BankInfoSecurity
6 months ago
Feds Warn Healthcare Sector of ScreenConnect Threats
CERT-EU
8 months ago
Municipalities Face a Constant Battle as Ransomware Snowballs | #ransomware | #cybercrime | National Cyber Security Consulting
DARKReading
8 months ago
Municipalities Face a Constant Battle as Ransomware Snowballs
CERT-EU
8 months ago
Cybersecurity attack steals Rock County Human Services info | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware | National Cyber Security Consulting
Securelist
8 months ago
Kaspersky malware report for Q3 2023
CERT-EU
8 months ago
Orgs still losing logs, powerless to speedy ransomware
CERT-EU
9 months ago
Veeam แจ้งเตือนช่องโหว่ระดับ critical บน Veeam ONE Monitoring Platform - Bangkok, Thailand | i-secure Co, Ltd.
CERT-EU
9 months ago
Veeam warns of critical bugs in Veeam ONE monitoring platform
BankInfoSecurity
9 months ago
Women Political Leaders Targeted With RomCom RAT Variant
CERT-EU
9 months ago
RomCom Malware Group Targets EU Gender Equality Summit
InfoSecurity-magazine
9 months ago
New RomCom Backdoor Targets Female Political Leaders
CERT-EU
9 months ago
Women Political Leaders Summit targeted in RomCom malware phishing
CERT-EU
9 months ago
New PEAPOD Cyberattack Campaign Targeting Women Political Leaders
CERT-EU
a year ago
Russia-Linked RomCom Hackers Targeting NATO Summit Guests
CERT-EU
a year ago
It's 2023 and Sri Lanka lacks a cyber security authority
Securelist
a year ago
Overview of ransomware trends in 2023
CERT-EU
a year ago
Microsoft Releases Patches for 132 Vulnerabilities, Including 6 Under Active Attack
Checkpoint
10 months ago
9th October – Threat Intelligence Report - Check Point Research
CERT-EU
10 months ago
Kaspersky provides update on Cuba ransomware gang | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware | National Cyber Security Consulting
CERT-EU
10 months ago
Cuba ransomware attack hits Wisconsin county's health department