Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how infostealer infections are impacting your business

Ransomware Group : cuba

cuba


The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted.<br> <br> Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site.<br> <br> According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in 2023, there were indications that the developer behind the Cuba ransomware speaks Russian.<br> <br> The ransomware operators use a double extortion approach, and following the USA, in August 2022, it was believed that the Cuba ransomware group had compromised 101 entities, demanding $145 million in ransom payments and receiving up to $60 million.<br> <br> The group used a similar set of TTPs, with only a slight change each year, as they generally consist of LOLBins (executables that are part of the operating system and can be exploited to support an attack), exploits, off-the-shelf and custom malware, as well as intrusion tools like Cobalt Strike and Metasploit.<br> <br> In 2022, the group allegedly developed a relationship with operators of the Industrial Spy market, using their platform as a means of data leakage.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs


Ransomware.live has 105 victims in its database for this group.

Victim Name Country Date
dms-imaging 2024-02-01
deknudtframes.be 2024-01-18
diagnostechs 2023-11-14
portadelaidefc 2023-11-13
panaya 2023-11-07
prime-art 2023-11-07
Newconcepttech 2023-10-23
mountstmarys 2023-10-10
co.rock.wi.us 2023-10-03
goldmedalbakery 2023-08-19
hydrex.co.uk 2023-07-31
txmplant.co.uk 2023-07-31
gis4.addison-il 2023-07-11
Inquirer 2023-05-23
Vdi 2023-05-10
Gihealthcare 2023-05-04
pu.edu.lb 2022-12-27
Sae-a 2022-12-20
2networkit 2022-12-12
Landaumedia 2022-12-01
Generator-power 2022-12-01
Boss-inc 2022-12-01
Patton 2022-11-30
Pmc-group 2022-11-24
waltersandwolf 2022-11-09
bfw 2022-11-04
Ville-chaville 2022-11-04
Murphyfamilyventures 2022-11-04
Ginspectionservices 2022-11-04
Dialogsas 2022-11-04
usairports 2022-11-04
trant.co.uk 2022-11-04
the_rose_executive_team 2022-11-04
technicote 2022-11-04
stm.com.tw 2022-11-04
site-technology_ 2022-11-04
schultheis-ins 2022-11-04
quercus 2022-11-04
otrcapital 2022-11-04
ohagin 2022-11-04
nwdusa 2022-11-04
ncmutuallife2 2022-11-04
meriplex 2022-11-04
megaforce 2022-11-04
lycra 2022-11-04
linkmfg 2022-11-04
learning_resources 2022-11-04
landofrost 2022-11-04
innovairre 2022-11-04
get-integrated 2022-11-04
gascaribe 2022-11-04
forefront_dermatology 2022-11-04
first_coast_logistics_services 2022-11-04
e.h._wachs_pipe_cutters 2022-11-04
datamatics 2022-11-04
creditriskmonitor 2022-11-04
blackhawk 2022-11-04
berding-weil 2022-11-04
bcintlgroup.com 2022-11-04
axley 2022-11-04
afts 2022-11-04
Skupstina 2022-11-04
ginspectionservices 2022-09-27
skupstina 2022-08-30
site-technology 2022-07-21
stm-com-tw 2022-07-07
r1group 2022-06-27
etron 2022-06-13
upskwt 2022-05-17
fronteousa 2022-05-16
prophoenix 2022-04-22
metrobrokers 2022-04-22
tavistock 2022-04-12
metagenics 2022-04-08
bcintlgroup-com 2022-03-30
trant-co-uk 2022-03-30
haltonhills 2022-03-23
powertech 2022-03-23
ids97 2022-02-25
muntons 2022-02-18
heritage-encon 2022-02-18
shoesforcrews 2022-02-04
edgo 2022-02-04
cmmcpas 2022-02-04
mtlcraft 2022-01-25
superfund 2022-01-13
fdcbuilding 2022-01-13
strongwell 2022-01-10
sonomatic-2 2022-01-10
regulvar 2022-01-10
delinebox 2022-01-10
cle 2022-01-10
squamish 2021-12-30
sonomatic 2021-12-30
ncmutuallife 2021-12-30
lahebert 2021-12-30
bakertilly 2021-12-30
atlasdie 2021-12-30
The Squamish Nation is comprised of descendants of the Coast Salish Aboriginal peoples who 2021-09-09
First Coast Logistics Services, Inc. was founded in 1999. The Company's line of business i 2021-09-09
Datamatics is a technology company that builds intelligent solutions enabling data-driven 2021-09-09
Rose Associates Mission Statement 2021-09-09
AFTS supplies the preeminent Payment Processing, IRS 1031 Exchange, Data Processing, Invoi 2021-09-09
OTR Capital believes in simple and straightforward transactions, without hidden costs and 2021-09-09
Automatic Funds Transfer Services Inc. (vendor to city of Bainbridge Island) 2021-02-03