Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Cuba / Colddraw

The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted.

Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site.

According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in 2023, there were indications that the developer behind the Cuba ransomware speaks Russian.

The ransomware operators use a double extortion approach, and following the USA, in August 2022, it was believed that the Cuba ransomware group had compromised 101 entities, demanding $145 million in ransom payments and receiving up to $60 million.

The group used a similar set of TTPs, with only a slight change each year, as they generally consist of LOLBins (executables that are part of the operating system and can be exploited to support an attack), exploits, off-the-shelf and custom malware, as well as intrusion tools like Cobalt Strike and Metasploit.

In 2022, the group allegedly developed a relationship with operators of the Industrial Spy market, using their platform as a means of data leakage.
Source: https://github.com/crocodyli/ThreatActors-TTPs
External information

Victims
105
 
First Discovered
2021-02-03
victim
Last Discovered
2024-02-01
victim
Inactive Since
2yrs
more than
Avg Delay
4
days
Infostealer
0.0%
victims with domain

View Victims on World Map

View group statistics


Known Locations (2)
Favicon Title Type Available Last Visit Server Info FQDN
favicon None No 2025-06-01 21:18:24 cuba4mp6ximo2zlo.onion
favicon Cuba No 2025-06-01 21:18:32 cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion

Target (Available)
Top 5 Activity Sectors
  • Financial 1
  • Manufacturing 1
  • Healthcare 1
Top 5 Countries
  • GB flag United Kingdom 3
  • US flag United States 2
  • TW flag Taiwan, Province of China 1
  • BE flag Belgium 1
  • FR flag France 1

Heatmap (Available)

Ransom Notes (1)

Tools Used (Available)
This information is provided by Ransomware-Tool-Matrix
Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration

NetSupport

Avast Anti-Rootkit driver

Mimikatz

Cobalt Strike

Meterpreter
Termite

PsExec



Vulnerabilities Exploited (0)

No vulnerabilities exploited available.


TTPs Matrix (7)
This information is provided by Crocodyli & Ransomware.live
Initial Access Execution Defense Evasion Discovery Lateral Movement Credential Access Command and Control
External Remote Services Native API Masquerading: Match Legitimate Name or Location Time Discovery Tool Transfer Exploitation for Credential Access Remote Desktop Protocol
Valid Accounts: Local Accounts User Execution: Malicious File Exploitation for Privilege Escalation Network Share Discovery External Remote Services Remote Services: External Remote Services Multi-hop Proxy
  Command and Scripting Interpreter: PowerShell   Remote System Discovery     Application Layer Protocol: DNS
  Command and Scripting Interpreter: Windows Command Shell   File and Directory Discovery     Application Layer Protocol: Web Protocols
  System Services: Service Execution   Process Discovery      
      Network Configuration Discovery: Network Connection Enumeration      

Negotiation Chats (0)

No negotiation chats available.


YARA Rules (0)

No YARA rules available.


Indicators of Compromise (IoCs) (0)

No IoCs available for this group.


Victims (105)
Logo
Discovered: 2024-02-01
DMS is a French industrial company specialized in digital radiology, with an international reach, an…
Logo
Discovered: 2024-01-22  ·  Attack est.: 2024-01-18
Our teamOur team in Deerlijk consists of enthusiastic and motivated people with passion for their pr…
Logo
Discovered: 2023-11-14
HistoryEstablished in 1987, DiagnosTechs was the first laboratory to introduce saliva hormone testin…
Logo
Discovered: 2023-11-13
PORT ADELAIDE is renowned for setting the bar high and expecting success, and the club’s latest stra…
Logo
Discovered: 2023-11-07
About PANAYAPanaya’s Change Intelligence solutions reduce the time, cost, and risk involved in chang…
Logo
Discovered: 2023-11-07
For PAJ, your success is our success.Jewelry making is an art and a science. We are constantly impro…
Logo
Discovered: 2023-10-23
FROM A SINGLE START-UP TO A MULTI-MILLION DOLLAR COMPANYOur prosperity is due to three interlocking …
Logo
Discovered: 2023-10-10
Mount St Mary’s is rightly proud of its extensive heritage dating back over 160 years. The original …
Logo
Discovered: 2023-10-03
Rock County Public Health DepartmentThe Rock County Public Health Department (RCPHD) is a level III …
Logo
Discovered: 2023-08-19
Gold Medal Bakery aspires to follow three core values in every aspect of its business.Integrity: Gol…
Logo
Discovered: 2023-07-31
Established in 1985, with 13 depots and one support centre nationwide, Hydrex is one of the largest …
Logo
Discovered: 2023-07-31
At TXM Plant we know that the services we provide are critical to the success of our customers’ proj…
Logo
Discovered: 2023-07-11
More than 36,000 people call the Village of Addison home.  Whether you are new to our community, or …
Logo
Discovered: 2023-05-23
About The Philadelphia Inquirer, PBCSince 1829, The Philadelphia Inquirer has been “asking on behalf…
Logo
Discovered: 2023-05-10
Užtikrindami oruma darbe mes užtikriname ir pamatines žmogaus teisesValstybines darbo inspekcijos (V…
Logo
Discovered: 2023-05-04
Your health is our top priority. We specialize in digestive system care and will guide you through e…
Logo
Discovered: 2022-12-27
Phoenicia University (PU) is a non-profit, private, and nonsectarian officially licensed institution…
Logo
Discovered: 2022-12-20
From yarn-production through its fabric mills that draw on in new innovation and technology, to reta…
Logo
Discovered: 2022-12-12
No description available
Logo
Discovered: 2022-12-01
No description available
Logo
Discovered: 2022-12-01
No description available
Logo
Discovered: 2022-12-01
No description available
Logo
Discovered: 2022-11-30
No description available
Logo
Discovered: 2022-11-24
No description available
Logo
Discovered: 2022-11-09
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-11-04
No description available
Logo
Discovered: 2022-09-27
No description available
Logo
Discovered: 2022-08-30
No description available
Logo
Discovered: 2022-07-21
No description available
Logo
Discovered: 2022-07-07
No description available
Logo
Discovered: 2022-06-27
No description available
Logo
Discovered: 2022-06-13
No description available
Logo
Discovered: 2022-05-17
No description available
Logo
Discovered: 2022-05-16
No description available
Logo
Discovered: 2022-04-22
No description available
Logo
Discovered: 2022-04-22
No description available
Logo
Discovered: 2022-04-12
No description available
Logo
Discovered: 2022-04-08
No description available
Logo
Discovered: 2022-03-30
No description available
Logo
Discovered: 2022-03-30
No description available
Logo
Discovered: 2022-03-23
No description available
Logo
Discovered: 2022-03-23
No description available
Logo
Discovered: 2022-02-25
No description available
Logo
Discovered: 2022-02-18
No description available
Logo
Discovered: 2022-02-18
No description available
Logo
Discovered: 2022-02-04
No description available
Logo
Discovered: 2022-02-04
No description available
Logo
Discovered: 2022-02-04
No description available
Logo
Discovered: 2022-01-25
No description available
Logo
Discovered: 2022-01-13
No description available
Logo
Discovered: 2022-01-13
No description available
Logo
Discovered: 2022-01-10
No description available
Logo
Discovered: 2022-01-10
No description available
Logo
Discovered: 2022-01-10
No description available
Logo
Discovered: 2022-01-10
No description available
Logo
Discovered: 2022-01-10
No description available
Logo
Discovered: 2021-12-30
No description available
Logo
Discovered: 2021-12-30
No description available
Logo
Discovered: 2021-12-30
No description available
Logo
Discovered: 2021-12-30
No description available
Logo
Discovered: 2021-12-30
No description available
Logo
Discovered: 2021-12-30
No description available
Logo
Discovered: 2021-09-09
No description available