Cuba
Parsing : Enabled
Known to be a RaaS
Description
Cuba ransomware, active since at least 2019, is a financially motivated threat group operating a double-extortion scheme—encrypting files and exfiltrating data to pressure victims. It has targeted government agencies, healthcare providers, critical infrastructure, financial institutions, and manufacturing firms, primarily in the United States, Canada, and Europe. Distribution often involves the Hancitor (Chanitor) malware loader, phishing campaigns, and exploitation of vulnerabilities in public-facing services such as Microsoft Exchange. Cuba employs RSA and AES encryption, typically appending the .cuba extension to affected files, and drops ransom notes instructing victims to contact the attackers via Tor-based portals. In December 2021, the FBI reported that Cuba ransomware operators had compromised at least 49 entities in U.S. critical infrastructure sectors, stealing data and demanding multimillion-dollar ransoms.
External Analysis |
https://www.mcafee.com/enterprise/en-us/assets/reports/rp-cuba-ransomware.pdf |
https://digital.nhs.uk/cyber-alerts/2021/cc-3855 |
https://blog.group-ib.com/hancitor-cuba-ransomware |
https://docs.google.com/spreadsheets/d/1MI8Z2tBhmqQ5X8Wf_ozv3dVjz5sJOs-3 |
https://id-ransomware.blogspot.com/2019/12/cuba-ransomware.html |
https://lab52.io/blog/cuba-ransomware-analysis/ |
https://shared-public-reports.s3-eu-west-1.amazonaws.com/Cuba+Ransomware+Group+-+on+a+roll.pdf |
https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius/ |
https://www.aon.com/cyber-solutions/aon_cyber_labs/yours-truly-signed-av-driver-weaponizing-an-antivirus-driver/ |
https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-cuba-ransomware/ |
https://www.elastic.co/security-labs/cuba-ransomware-campaign-analysis |
https://www.elastic.co/security-labs/cuba-ransomware-malware-analysis |
https://www.fortinet.com/blog/threat-research/ransomware-roundup-gwisin-kriptor-cuba-and-more |
https://www.guidepointsecurity.com/blog/using-hindsight-to-close-a-cuba-cold-case/ |
https://www.ic3.gov/Media/News/2021/211203-2.pdf |
https://www.it-connect.fr/le-ransomware-cuba-sen-prend-aux-serveurs-exchange/ |
https://www.mandiant.com/resources/unc2596-cuba-ransomware |
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-atr-threat-report-a-quick-primer-on-cuba-ransomware |
https://www.mcafee.com/enterprise/en-us/assets/reports/rp-cuba-ransomware.pdf |
https://www.trendmicro.com/en_us/research/22/f/cuba-ransomware-group-s-new-variant-found-using-optimized-infect.html |
Tox |
37790E2D198DFD20C9D2887D4EF7C3E2951BB84248D192689B64DCCA3C8BD808A1895676B271 |
Urls |
Screen |
http://cuba4mp6ximo2zlo.onion |
Screen |
http://cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion/ |
Screen |
File servers |
Screen |
http://i34gbmo5rxx3bxc4yl7f4erkyo2oldwavhpdragnjjvhni6fwvptp2id.onion |
|
https://kcfgfs7cclscxloy3bf2xtwnayimawtzrbfirfbvl47xt7n2brfiizyd.onion/ |
|
Posts
Date |
Title |
Description |
Screen |
2024-02-01 |
dms-imaging |
|
Screen |
2024-01-22 |
deknudtframes.be |
|
Screen |
2023-11-14 |
diagnostechs |
|
Screen |
2023-11-13 |
portadelaidefc |
|
Screen |
2023-11-07 |
panaya |
|
Screen |
2023-11-07 |
prime-art |
|
Screen |
2023-10-23 |
Newconcepttech |
|
Screen |
2023-10-10 |
mountstmarys |
|
Screen |
2023-10-03 |
co.rock.wi.us |
|
Screen |
2023-08-19 |
goldmedalbakery |
|
Screen |
2023-07-31 |
hydrex.co.uk |
|
Screen |
2023-07-31 |
txmplant.co.uk |
|
Screen |
2023-07-11 |
gis4.addison-il |
|
Screen |
2023-05-23 |
Inquirer |
|
|
2023-05-10 |
Vdi |
|
Screen |
2023-05-04 |
2networkit |
|
Screen |
2023-05-04 |
Sae-a |
|
Screen |
2023-05-04 |
pu.edu.lb |
|
Screen |
2023-05-04 |
Gihealthcare |
|
Screen |
2023-05-04 |
cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion |
|
Screen |
2022-12-02 |
learning_resources |
|
Screen |
2022-12-02 |
usairports |
|
Screen |
2022-12-02 |
first_coast_logistics_services |
|
Screen |
2022-12-02 |
e.h._wachs_pipe_cutters |
|
Screen |
2022-12-02 |
datamatics |
|
Screen |
2022-12-02 |
the_rose_executive_team |
|
Screen |
2022-12-02 |
afts |
|
Screen |
2022-12-02 |
otrcapital |
|
Screen |
2022-12-02 |
forefront_dermatology |
|
Screen |
2022-12-02 |
innovairre |
|
Screen |
2022-12-02 |
megaforce |
|
Screen |
2022-12-02 |
gascaribe |
|
Screen |
2022-12-02 |
quercus |
|
Screen |
2022-12-02 |
blackhawk |
|
Screen |
2022-12-02 |
lycra |
|
Screen |
2022-12-02 |
technicote |
|
Screen |
2022-12-02 |
berding-weil |
|
Screen |
2022-12-02 |
nwdusa |
|
Screen |
2022-12-02 |
creditriskmonitor |
|
Screen |
2022-12-02 |
linkmfg |
|
Screen |
2022-12-02 |
axley |
|
Screen |
2022-12-02 |
schultheis-ins |
|
Screen |
2022-12-02 |
meriplex |
|
Screen |
2022-12-02 |
ohagin |
|
Screen |
2022-12-02 |
landofrost |
|
Screen |
2022-12-02 |
ncmutuallife2 |
|
Screen |
2022-12-02 |
get-integrated |
|
Screen |
2022-12-02 |
trant.co.uk |
|
Screen |
2022-12-02 |
bcintlgroup.com |
|
Screen |
2022-12-02 |
stm.com.tw |
|
Screen |
2022-12-02 |
site-technology_ |
|
Screen |
2022-12-02 |
Skupstina |
|
Screen |
2022-12-02 |
Ginspectionservices |
|
Screen |
2022-12-02 |
Murphyfamilyventures |
|
Screen |
2022-12-02 |
Ville-chaville |
|
Screen |
2022-12-02 |
Dialogsas |
|
Screen |
2022-12-02 |
bfw |
|
Screen |
2022-12-02 |
waltersandwolf |
|
Screen |
2022-12-02 |
Patton |
|
Screen |
2022-12-02 |
Boss-inc |
|
Screen |
2022-12-02 |
Landaumedia |
|
Screen |
2022-12-02 |
Generator-power |
|
Screen |
2022-12-02 |
company |
|
|
2022-09-27 |
ginspectionservices |
|
|
2022-08-30 |
skupstina |
|
|
2022-08-18 |
site-technology |
|
|
2022-07-12 |
stm-com-tw |
|
|
2022-07-02 |
r1group |
|
Screen |
2022-06-13 |
etron |
|
Screen |
2022-05-17 |
upskwt |
|
Screen |
2022-05-16 |
fronteousa |
|
|
2022-04-22 |
prophoenix |
|
Screen |
2022-04-22 |
metrobrokers |
|
Screen |
2022-04-12 |
tavistock |
|
|
2022-04-08 |
metagenics |
|
Screen |
2022-03-30 |
trant-co-uk |
|
|
2022-03-30 |
bcintlgroup-com |
|
|
2022-03-23 |
haltonhills |
|
|
2022-03-23 |
powertech |
|
Screen |
2022-02-25 |
ids97 |
|
|
2022-02-18 |
muntons |
|
Screen |
2022-02-18 |
heritage-encon |
|
|
2022-02-04 |
cmmcpas |
|
Screen |
2022-02-04 |
shoesforcrews |
|
Screen |
2022-02-04 |
edgo |
|
Screen |
2022-01-25 |
mtlcraft |
|
Screen |
2022-01-13 |
superfund |
|
Screen |
2022-01-13 |
fdcbuilding |
|
Screen |
2022-01-10 |
cle |
|
Screen |
2022-01-10 |
strongwell |
|
Screen |
2022-01-10 |
sonomatic-2 |
|
|
2022-01-10 |
regulvar |
|
Screen |
2022-01-10 |
delinebox |
|
Screen |
2021-12-29 |
squamish |
|
Screen |
2021-12-29 |
bakertilly |
|
Screen |
2021-12-29 |
sonomatic |
|
Screen |
2021-12-29 |
atlasdie |
|
Screen |
2021-12-29 |
ncmutuallife |
|
Screen |
2021-12-29 |
lahebert |
|
Screen |
2021-09-09 |
The Squamish Nation is comprised of descendants of the Coast Salish Aboriginal peoples who |
|
|
2021-09-09 |
First Coast Logistics Services, Inc. was founded in 1999. The Company's line of business i |
|
|
2021-09-09 |
Datamatics is a technology company that builds intelligent solutions enabling data-driven |
|
|
2021-09-09 |
Rose Associates Mission Statement |
|
|
2021-09-09 |
AFTS supplies the preeminent Payment Processing, IRS 1031 Exchange, Data Processing, Invoi |
|
|
2021-09-09 |
OTR Capital believes in simple and straightforward transactions, without hidden costs and |
|
|