Cuba
MITRE ATT&CK: S0625 View on attack.mitre.org
Aliases: COLDDRAW, Fidel, Cuba
- First seen
- 2019-12-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Operating systems
- windows
- Related IoCs
- 4 (4 malicious)
- Last IoC activity
- 2026-08-12 12:25:50
- Profile updated
- 2026-07-07 13:44:07
Targeted industries: financial-services technology-and-telecommunications transportation-and-logistics
Targeted regions: country_code:us country_code:br country_code:gb
Context
Cuba is a Windows-based ransomware family that has been used against financial institutions, technology, and logistics organizations in North and South America as well as Europe since at least December 2019.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to Cuba (S0625). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 7cea1d834dee8dffba2cc7f59a1a558a79a08c3f6a2b8ce35593cadf4e4b7277 | 2026-08-12 | 1 |
| file sample | 2026-06-04_7e5acd3da28f7cb0ef653a1a62b38e4e_amadey_coinminer_elex_emotet_hell... | 2026-06-04 | 1 |
| file sample | sub_0a3517d8d382.bin | 2026-05-24 | 1 |
| file sample | 482b160ee2e8d94fa6e4749f77e87da89c9658e7567459bc633d697430e3ad9a.bin | 2025-02-16 | 1 |
Detection coverage
- 1 YARA rules
- 543 Sigma rules
Malware & tools used
- Local Storage Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Software Packing (attack-pattern)
- Native API (attack-pattern)
- System Language Discovery (attack-pattern)
- Data Encrypted for Impact (attack-pattern)
- Network Share Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- File Deletion (attack-pattern)
- Reflective Code Loading (attack-pattern)
- PowerShell (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Keylogging (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Service Stop (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- System Service Discovery (attack-pattern)
- Process Discovery (attack-pattern)
- Access Token Manipulation (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Hidden Window (attack-pattern)
Used by threat actors
- Void Rabisu (threat-actor)
Detection rules
- MALPEDIA_Win_Cuba_Auto (yara-rule)
Reports & references
- docs.google.com — 1Mi8Z2Tbhmqq5X8Wf Ozv3Dvjz5Sjos 3 (report)
- McAfee — Rp Cuba Ransomware (report)
- digital.nhs.uk — Cc 3855 (report)
- blog.group-ib.com — Hancitor Cuba Ransomware (report)
- id-ransomware.blogspot.com — Cuba Ransomware (report)
- lab52.io — Cuba Ransomware Analysis (report)
- shared-public-reports.s3-eu-west-1.amazonaws.com — Cuba+Ransomware+Group+ +On+A+Roll (report)
- Palo Alto Unit 42 — Cuba Ransomware Tropical Scorpius (report)
- aon.com — Yours Truly Signed Av Driver Weaponizing An Antivirus Driver (report)
- bleepingcomputer.com — Microsoft Exchange Servers Hacked To Deploy Cuba Ransomware (report)
- elastic.co — Cuba Ransomware Campaign Analysis (report)
- elastic.co — Cuba Ransomware Malware Analysis (report)
- fortinet.com — Ransomware Roundup Gwisin Kriptor Cuba And More (report)
- guidepointsecurity.com — Using Hindsight To Close A Cuba Cold Case (report)
- ic3.gov — 211203 2 (report)
- it-connect.fr — Le Ransomware Cuba Sen Prend Aux Serveurs Exchange (report)
- Mandiant — Unc2596 Cuba Ransomware (report)
- McAfee — Mcafee Atr Threat Report A Quick Primer On Cuba Ransomware (report)
- Trend Micro — Cuba Ransomware Group S New Variant Found Using Optimized Infect (report)
- ransomlook.io — Cuba (report)
- blogs.blackberry.com — Cuba Ransomware Deploys New Tools Targets Critical Infrastructure Sector In The Usa And It Integrator In Latin America (report)
- Mandiant — Unc2596 Cuba Ransomware (report)
- CISA — Aa22 335A (report)
- profero.io — Cuba Ransomware Group On A Roll (report)
- noticeofpleadings.com — 1%20 Microsoft%20Cobalt%20Strike%20 %20Complaint(907040021.9) (report)