Ransomware Group intelligence
Cuba
InactiveTrack Cuba with 105 published victims and 2 known leak locations in a single intelligence view.
Overview
Cuba is tracked by Breach House as a ransomware group with 105 published victims.
United Kingdom is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Down checked 2h ago | cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion |
| Leak location 1 | Onion service | Down checked 2h ago | cuba4mp6ximo2zlo.onion |
Top Activity Sectors (14)
- Not identified 61
- Services 11
- Communication / Marketing 10
- IT 7
- Public Sector 3
- Manufacturing / Engineering 2
- Education 2
- Energy 2
- Transportation / Travel / Logistics 2
- Hospitality / Food & Beverage / Tourism 1
- Healthcare / Pharma 1
- Telecommunications 1
- Finance / Legal / Insurance 1
- Construction / Real Estate 1
Typical Attacks (23)
▼How Cuba typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via Cuba.
-
T1059.001 PowerShell Execution
What they do: Cuba has been dropped onto systems and used for lateral movement via obfuscated PowerShell scripts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1059.003 Windows Command Shell Execution
What they do: Cuba has used cmd.exe /c and batch files for execution.
What that means: Adversaries may abuse the Windows command shell for execution.
-
T1106 Native API Execution
What they do: Cuba has used several built-in API functions for discovery like GetIpNetTable and NetShareEnum.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: Cuba can modify services by using the OpenService and ChangeServiceConfig functions.
What that means: Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
-
What they do: Cuba has used SeDebugPrivilege and AdjustTokenPrivileges to elevate privileges.
What that means: Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
-
T1027 Obfuscated Files or Information Stealth
What they do: Cuba has used multiple layers of obfuscation to avoid analysis, including its Base64 encoded payload.
What that means: Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
-
T1027.002 Software Packing Stealth
What they do: Cuba has a packed payload when delivered.
What that means: Adversaries may perform software packing or virtual machine software protection to conceal their code.
-
T1036.005 Match Legitimate Resource Name or Location Stealth
What they do: Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs.
What that means: Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
-
T1070.004 File Deletion Stealth
What they do: Cuba can use the command cmd.exe /c del to delete its artifacts from the system.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1564.003 Hidden Window Stealth
What they do: Cuba has executed hidden PowerShell windows.
What that means: Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
-
T1620 Reflective Code Loading Stealth
What they do: Cuba loaded the payload into memory using PowerShell.
What that means: Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads.
-
What they do: Cuba logs keystrokes via polling by using GetKeyState and VkKeyScan functions.
What that means: Adversaries may log user keystrokes to intercept credentials as the user types them.
-
T1007 System Service Discovery Discovery
What they do: Cuba can query service status using QueryServiceStatusEx function.
What that means: Adversaries may try to gather information about registered local system services.
-
T1016 System Network Configuration Discovery Discovery
What they do: Cuba can retrieve the ARP cache from the local system by using GetIpNetTable.
What that means: Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
-
T1049 System Network Connections Discovery Discovery
What they do: Cuba can use the function GetIpNetTable to recover the last connections to the victim's machine.
What that means: Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
-
T1057 Process Discovery Discovery
What they do: Cuba can enumerate processes running on a victim's machine.
What that means: Adversaries may attempt to get information about running processes on a system.
-
T1083 File and Directory Discovery Discovery
What they do: Cuba can enumerate files by using a variety of functions.
What that means: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
-
T1135 Network Share Discovery Discovery
What they do: Cuba can discover shared resources using the NetShareEnum API call.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1614.001 System Language Discovery Discovery
What they do: Cuba can check if Russian language is installed on the infected machine by using the function GetKeyboardLayoutList.
What that means: Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
-
T1680 Local Storage Discovery Discovery
What they do: Cuba can enumerate local drives, disk type, and disk free space.
What that means: Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
-
T1105 Ingress Tool Transfer Command and Control
What they do: Cuba can download files from its C2 server.
What that means: Adversaries may transfer tools or other files from an external system into a compromised environment.
-
T1486 Data Encrypted for Impact Impact
What they do: Cuba has the ability to encrypt system data and add the ".cuba" extension to encrypted files.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1489 Service Stop Impact
What they do: Cuba has a hardcoded list of services and processes to terminate.
What that means: Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
Tools Observed (7)
▼Software Cuba has been seen using, grouped by what it is used for. Legitimate administration tools appear here because these actors routinely abuse them — presence in this list is not itself malicious.
Credential theft
Defense evasion
LOLBAS (living-off-the-land binaries)
Networking & tunnelling
Offensive security tooling
Remote monitoring & management
Tool data from Ransomware Tool Matrix by BushidoUK, licensed CC BY 4.0. Grouped by purpose and matched to this group by Breach House.
Crypto Wallets (18)
▼| Address | Chain | Received (USD) | Payments |
|---|---|---|---|
bc1qhtwfcysclc7pck2y3vmjtpzkaezhcm6perc99x |
bitcoin | $13,353,784 | 1 |
bc1q6zkemtyyrre2mkk23g93zyq98ygrygvx7z2q0t |
bitcoin | $10,163,533 | 1 |
bc1q6rsj3cn37dngypu5kad9gdw5ykhctpwhjvun3z |
bitcoin | $9,977,496 | 2 |
bc1qvpk8ksl3my6kjezjss9p28cqj4dmpmmjx5yl3y |
bitcoin | $8,122,149 | 1 |
bc1qft3s53ur5uq5ru6sl3zyr247dpr55mnggwucd3 |
bitcoin | $4,309,411 | 1 |
bc1qr9l0gcl0nvmngap6ueyy5gqdwvm34kdmtevjyx |
bitcoin | $4,094,333 | 1 |
bc1q9cj0n9k2m282x0nzj6lhqjvhkkd4h95sewek83 |
bitcoin | $3,252,361 | 1 |
bc1q4vr25xkth35qslenqwd7aw020w85qrvlrhv7hc |
bitcoin | $1,590,573 | 1 |
bc1qaselp9nhejc3safcq3vn5wautx6w33x0llk7dl |
bitcoin | $1,162,302 | 1 |
bc1q5uc0fdnz0ve5pg4nl4upa9ly586t6wmnghfe7x |
bitcoin | $983,731 | 1 |
bc1qzz7xweq8ee2j35tq6r5m687kctq9huskt50edv |
bitcoin | $798,321 | 1 |
bc1qp7h9fszlqxjwyfhv0upparnsgx56x7v7wfx4x7 |
bitcoin | $692,419 | 1 |
+6 more wallets not shown (the 12 largest by amount received are listed).
Crowdsourced payment data from Ransomwhere, licensed CC BY 4.0. Figures are what has been reported and attributed to this family, not a confirmed total. Cite as: Cable, Jack. (2024). Ransomwhere: A Crowdsourced Ransomware Payment Dataset (1.1.0) [Data set]. Zenodo. https://doi.org/10.5281/zenodo.6512122
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
cuba.txt
Good day. All your files are encrypted. For decryption contact us. Write here [email protected] reserve [email protected] jabber [email protected] We also inform that your databases, ftp server and file server were downloaded by us to our servers. If we do not receive a message from you within three days, we regard this as a refusal to negotiate. Check our platform: http://cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion/ * Do not rename encrypted files. * Do not try to decrypt your data using third party software, it may cause permanent data loss. * Do not stop process of encryption, because partial encryption cannot be decrypted.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (105)
Search, filter and paginate the victim timeline for Cuba. Showing 101–105 of 105.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Datamatics is a technology company that builds intelligent solutions enabling data-driven id1154 View details | IT | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Rose Associates Mission Statement id1153 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | AFTS supplies the preeminent Payment Processing, IRS 1031 Exchange, Data Processing, Invoi id1152 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | OTR Capital believes in simple and straightforward transactions, without hidden costs and id1151 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Automatic Funds Transfer Services Inc. (vendor to city of Bainbridge Island) id575 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||