Ransomware Group intelligence
Cuba
InactiveTrack Cuba with 105 published victims and 2 known leak locations in a single intelligence view.
Overview
Cuba is tracked by Breach House as a ransomware group with 105 published victims.
United Kingdom is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 2h ago | cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion |
| Leak location 1 | Onion service | Down checked 2h ago | cuba4mp6ximo2zlo.onion |
Top Activity Sectors (14)
- Not identified 61
- Services 11
- Communication / Marketing 10
- IT 7
- Public Sector 3
- Manufacturing / Engineering 2
- Education 2
- Energy 2
- Transportation / Travel / Logistics 2
- Hospitality / Food & Beverage / Tourism 1
- Healthcare / Pharma 1
- Telecommunications 1
- Finance / Legal / Insurance 1
- Construction / Real Estate 1
Typical Attacks (23)
▼How Cuba typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Cuba.
-
T1059.001 PowerShell Execution
What they do: Cuba has been dropped onto systems and used for lateral movement via obfuscated PowerShell scripts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Cuba has used cmd.exe /c and batch files for execution.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Cuba has used several built-in API functions for discovery like GetIpNetTable and NetShareEnum.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: Cuba can modify services by using the OpenService and ChangeServiceConfig functions.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
What they do: Cuba has used SeDebugPrivilege and AdjustTokenPrivileges to elevate privileges.
What that means: Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
-
T1027 Obfuscated Files or Information Stealth
What they do: Cuba has used multiple layers of obfuscation to avoid analysis, including its Base64 encoded payload.
What that means: Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
-
T1027.002 Software Packing Stealth
What they do: Cuba has a packed payload when delivered.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: Cuba can use the command cmd.exe /c del to delete its artifacts from the system.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1564.003 Hidden Window Stealth
What they do: Cuba has executed hidden PowerShell windows.
What that means: Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
-
T1620 Reflective Code Loading Stealth
What they do: Cuba loaded the payload into memory using PowerShell.
What that means: Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads.
-
What they do: Cuba logs keystrokes via polling by using GetKeyState and VkKeyScan functions.
What that means: Adversaries may log user keystrokes to intercept credentials as the user types them.
-
T1007 System Service Discovery Discovery
What they do: Cuba can query service status using QueryServiceStatusEx function.
What that means: Adversaries may try to gather information about registered local system services.
-
T1016 System Network Configuration Discovery Discovery
What they do: Cuba can retrieve the ARP cache from the local system by using GetIpNetTable.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1049 System Network Connections Discovery Discovery
What they do: Cuba can use the function GetIpNetTable to recover the last connections to the victim's machine.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1057 Process Discovery Discovery
What they do: Cuba can enumerate processes running on a victim's machine.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1083 File and Directory Discovery Discovery
What they do: Cuba can enumerate files by using a variety of functions.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Cuba can discover shared resources using the NetShareEnum API call.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1614.001 System Language Discovery Discovery
What they do: Cuba can check if Russian language is installed on the infected machine by using the function GetKeyboardLayoutList.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1680 Local Storage Discovery Discovery
What they do: Cuba can enumerate local drives, disk type, and disk free space.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Cuba can download files from its C2 server.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1486 Data Encrypted for Impact Impact
What they do: Cuba has the ability to encrypt system data and add the ".cuba" extension to encrypted files.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Cuba has a hardcoded list of services and processes to terminate.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
Tools Observed (7)
▼Software Cuba has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (18)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1qhtwfcysclc7pck2y3vmjtpzkaezhcm6perc99x |
bitcoin | $13,353,784 | 1 |
bc1q6zkemtyyrre2mkk23g93zyq98ygrygvx7z2q0t |
bitcoin | $10,163,533 | 1 |
bc1q6rsj3cn37dngypu5kad9gdw5ykhctpwhjvun3z |
bitcoin | $9,977,496 | 2 |
bc1qvpk8ksl3my6kjezjss9p28cqj4dmpmmjx5yl3y |
bitcoin | $8,122,149 | 1 |
bc1qft3s53ur5uq5ru6sl3zyr247dpr55mnggwucd3 |
bitcoin | $4,309,411 | 1 |
bc1qr9l0gcl0nvmngap6ueyy5gqdwvm34kdmtevjyx |
bitcoin | $4,094,333 | 1 |
bc1q9cj0n9k2m282x0nzj6lhqjvhkkd4h95sewek83 |
bitcoin | $3,252,361 | 1 |
bc1q4vr25xkth35qslenqwd7aw020w85qrvlrhv7hc |
bitcoin | $1,590,573 | 1 |
bc1qaselp9nhejc3safcq3vn5wautx6w33x0llk7dl |
bitcoin | $1,162,302 | 1 |
bc1q5uc0fdnz0ve5pg4nl4upa9ly586t6wmnghfe7x |
bitcoin | $983,731 | 1 |
bc1qzz7xweq8ee2j35tq6r5m687kctq9huskt50edv |
bitcoin | $798,321 | 1 |
bc1qp7h9fszlqxjwyfhv0upparnsgx56x7v7wfx4x7 |
bitcoin | $692,419 | 1 |
+6 more wallets not shown (the 12 largest by amount received are listed).
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
cuba.txt
Good day. All your files are encrypted. For decryption contact us. Write here [email protected] reserve [email protected] jabber [email protected] We also inform that your databases, ftp server and file server were downloaded by us to our servers. If we do not receive a message from you within three days, we regard this as a refusal to negotiate. Check our platform: http://cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion/ * Do not rename encrypted files. * Do not try to decrypt your data using third party software, it may cause permanent data loss. * Do not stop process of encryption, because partial encryption cannot be decrypted.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (105)
Search, filter and paginate the victim timeline for Cuba. Showing 1–100 of 105.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | dms-imaging id10639 View details | France | Manufacturing / Engineering | — | |
|
DMS is a French industrial company specialized in digital radiology, with an international reach, and recognized as a key actor and an indispensable partner in creating value through the quality of our solutions as well as our... |
|||||
| Ransomware | deknudtframes.be id10501 View details | Belgium | Communication / Marketing | ||
|
Our teamOur team in Deerlijk consists of enthusiastic and motivated people with passion for their profession. The management, sales, logistics, purchasing, accounting, customer service and marketing are ready for you on a daily... |
|||||
| Ransomware | diagnostechs id9538 View details | IT | — | ||
|
HistoryEstablished in 1987, DiagnosTechs was the first laboratory to introduce saliva hormone testing into routine clinical practice. In 1995, DiagnosTechs added saliva and stool-based gastrointestinal and food sensitivity testing,... |
|||||
| Ransomware | portadelaidefc id9529 View details | Australia | Hospitality / Food & Beverage / Tourism | — | |
|
PORT ADELAIDE is renowned for setting the bar high and expecting success, and the club’s latest strategic vision embraces that expectation.Unveiled at the club’s Annual General Meeting on Friday night, Chasing Greatness is... |
|||||
| Ransomware | panaya id9421 View details | Services | — | ||
|
About PANAYAPanaya’s Change Intelligence solutions reduce the time, cost, and risk involved in change to business applications like SAP®, Oracle® EBS, and Salesforce.com. Date the files were received: 02... |
|||||
| Ransomware | prime-art id9420 View details | Communication / Marketing | — | ||
|
For PAJ, your success is our success.Jewelry making is an art and a science. We are constantly improving and optimizing our skills while integrating cutting-edge technology.By always delivering a troy grain more than anticipated, we... |
|||||
| Ransomware | Newconcepttech id9200 View details | IT | — | ||
|
FROM A SINGLE START-UP TO A MULTI-MILLION DOLLAR COMPANYOur prosperity is due to three interlocking factors: the first, being our customers, who have always come first.The second, our employees, who are passionate about serving our... |
|||||
| Ransomware | mountstmarys id9030 View details | Communication / Marketing | — | ||
|
Mount St Mary’s is rightly proud of its extensive heritage dating back over 160 years. The original vision to educate all young people in the local area remains at the core of our work. Our mission is to ensure individual... |
|||||
| Ransomware | co.rock.wi.us id8943 View details | United States | Public Sector | — | |
|
Rock County Public Health DepartmentThe Rock County Public Health Department (RCPHD) is a level III health department in Rock County, Wisconsin. Our staff serves over 160,000 people in more than 25 cities, villages, and towns. As a... |
|||||
| Ransomware | goldmedalbakery id8203 View details | Services | |||
|
Gold Medal Bakery aspires to follow three core values in every aspect of its business.Integrity: Gold Medal has built its reputation on meeting the needs of our customers and the millions of consumers they serve. Thus, integrity is... |
|||||
| Ransomware | hydrex.co.uk id7982 View details | United Kingdom | Services | ||
|
Established in 1985, with 13 depots and one support centre nationwide, Hydrex is one of the largest suppliers of outsourced mobile plant solutions in the UK.Hydrex has a fleet totaling over 1200 machines. The company has invested in... |
|||||
| Ransomware | txmplant.co.uk id7981 View details | United Kingdom | Communication / Marketing | ||
|
At TXM Plant we know that the services we provide are critical to the success of our customers’ projects. That’s why we put the customer at the centre of everything that we do.Awarded ‘Gold’ standard in Network... |
|||||
| Ransomware | gis4.addison-il id7217 View details | Other | |||
|
More than 36,000 people call the Village of Addison home. Whether you are new to our community, or have lived here for years, we want you to get acquainted with our community. We also want to make it easy for you to stay... |
|||||
| Ransomware | Inquirer id6522 View details | Communication / Marketing | |||
|
About The Philadelphia Inquirer, PBCSince 1829, The Philadelphia Inquirer has been “asking on behalf of the people” of Philadelphia and the region by providing essential journalism. Locally owned and headquartered in... |
|||||
| Ransomware | Vdi id6396 View details | Lithuania | Communication / Marketing | ||
|
Užtikrindami oruma darbe mes užtikriname ir pamatines žmogaus teisesValstybines darbo inspekcijos (VDI) misija – orus darbas. Spalio 7-aja minint Diena už oru darba VDI primena, kad tarpusavio pagarba ir saugumas darbe saugo... |
|||||
| Ransomware | Gihealthcare id6336 View details | Healthcare / Pharma | |||
|
Your health is our top priority. We specialize in digestive system care and will guide you through every step – whether it’s a routine colon screening, major liver or pancreas issue, or a weight loss journey. With three... |
|||||
| Ransomware | pu.edu.lb id5139 View details | Education | — | ||
|
Phoenicia University (PU) is a non-profit, private, and nonsectarian officially licensed institution of higher education. The University comprises six colleges: Architecture and Design, Arts and Sciences, Business, Engineering, Law... |
|||||
| Ransomware | Sae-a id4917 View details | Manufacturing / Engineering | — | ||
|
From yarn-production through its fabric mills that draw on in new innovation and technology, to retail operations in Korea, SAE-A has become one of the few apparel manufacturers capable of achieving complete vertical-integration of... |
|||||
| Ransomware | 2networkit id4823 View details | Telecommunications | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Landaumedia id4694 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Generator-power id4693 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Boss-inc id4692 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Patton id4690 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pmc-group id4648 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | waltersandwolf id4548 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | bfw id4494 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ville-chaville id4493 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Murphyfamilyventures id4492 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ginspectionservices id4491 View details | Services | — | ||
|
Ginspectionservices, also known as Global Inspection Services (GIS), is a services company based in Madrid, Spain, with additional offices across Europe, the Americas, the Middle East and Asia. It provides inspection, testing and certification services for EPC firms, owners and vendors, and its website lists cargo and loading inspection, shipping quality and quantity inspection, and survey sampling testing among its offerings. The company also describes technical inspection work for mechanical and electrical equipment. It was listed as a ransomware victim associated with Cuba. |
|||||
| Ransomware | Dialogsas id4490 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | usairports id4489 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | trant.co.uk id4488 View details | United Kingdom | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | the_rose_executive_team id4487 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | technicote id4486 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | stm.com.tw id4485 View details | Taiwan, Province of China | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | site-technology_ id4484 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | schultheis-ins id4483 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | quercus id4482 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | otrcapital id4481 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ohagin id4480 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | nwdusa id4479 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ncmutuallife2 id4478 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | meriplex id4477 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | megaforce id4476 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | lycra id4475 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | linkmfg id4474 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | learning_resources id4473 View details | Education | — | ||
|
No additional victim description available. |
|||||
| Ransomware | landofrost id4472 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | innovairre id4471 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | get-integrated id4470 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | gascaribe id4469 View details | Energy | — | ||
|
No additional victim description available. |
|||||
| Ransomware | forefront_dermatology id4468 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | first_coast_logistics_services id4467 View details | Transportation / Travel / Logistics | — | ||
|
No additional victim description available. |
|||||
| Ransomware | e.h._wachs_pipe_cutters id4466 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | datamatics id4465 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | creditriskmonitor id4464 View details | Finance / Legal / Insurance | — | ||
|
No additional victim description available. |
|||||
| Ransomware | blackhawk id4463 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | berding-weil id4462 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | bcintlgroup.com id4461 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | axley id4460 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | afts id4459 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Skupstina id4458 View details | Other | — | ||
|
Skupstina is an organization in the Business, Professional, Labor, Political, and Similar Organizations sector, with a registered address in Niš, Serbia. Business-directory records place it at Bulevar Dr. Zorana Đinđića 121/A in the Medijana area of the city, and identify it as a local organizational entity. In threat-intelligence catalogs, it is recorded as a ransomware victim. The listing associates Skupstina with the threat actor cuba. |
|||||
| Ransomware | ginspectionservices id4246 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | skupstina id4048 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | site-technology id3841 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | stm-com-tw id3758 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | r1group id3689 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | etron id3626 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | upskwt id3456 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | fronteousa id3447 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | prophoenix id3251 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | metrobrokers id3250 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | tavistock id3142 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | metagenics id3113 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | bcintlgroup-com id3015 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | trant-co-uk id3013 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | haltonhills id2944 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | powertech id2938 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ids97 id2725 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | muntons id2651 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | heritage-encon id2650 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | shoesforcrews id2549 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | edgo id2548 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | cmmcpas id2547 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | mtlcraft id2481 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | superfund id2436 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | fdcbuilding id2435 View details | Construction / Real Estate | — | ||
|
No additional victim description available. |
|||||
| Ransomware | strongwell id2421 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | sonomatic-2 id2420 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | regulvar id2419 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | delinebox id2418 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | cle id2417 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | squamish id2312 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | sonomatic id2311 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ncmutuallife id2310 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | lahebert id2309 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | bakertilly id2308 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | atlasdie id2307 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | The Squamish Nation is comprised of descendants of the Coast Salish Aboriginal peoples who id1156 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | First Coast Logistics Services, Inc. was founded in 1999. The Company's line of business i id1155 View details | Services | — | ||
|
No additional victim description available. |
|||||