Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Cuba / Colddraw

The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted.

Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site.

According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in 2023, there were indications that the developer behind the Cuba ransomware speaks Russian.

The ransomware operators use a double extortion approach, and following the USA, in August 2022, it was believed that the Cuba ransomware group had compromised 101 entities, demanding $145 million in ransom payments and receiving up to $60 million.

The group used a similar set of TTPs, with only a slight change each year, as they generally consist of LOLBins (executables that are part of the operating system and can be exploited to support an attack), exploits, off-the-shelf and custom malware, as well as intrusion tools like Cobalt Strike and Metasploit.

In 2022, the group allegedly developed a relationship with operators of the Industrial Spy market, using their platform as a means of data leakage.
Source: https://github.com/crocodyli/ThreatActors-TTPs
External information

Victims
103
 
First Discovered
2021-02-03
victim
Last Discovered
2024-02-01
victim
Inactive Since
2yrs
more than
Avg Delay
4
days
Infostealer
41.7%
victims with domain
Countries
7
hit
View Victims on World Map View Group Statistics

Known Locations (2)
Favicon Title Type Available Last Visit Server Info FQDN
favicon No 2026-04-28T07:21:48 cuba4mp6ximo2zlo.onion
favicon Cuba No 2026-04-28T07:22:15 cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion

Target
Top 5 Activity Sectors
  • Manufacturing 14
  • Technology 11
  • Business Services 11
  • Financial Services 11
  • Public Sector 7
Top 5 Countries
  • GB flag United Kingdom 3
  • US flag United States 2
  • FR flag France 1
  • BE flag Belgium 1
  • AU flag Australia 1

Heatmap

Ransom Notes (1)

Tools Used
This information is provided by Ransomware-Tool-Matrix
Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration

NetSupport

Avast Anti-Rootkit driver

Mimikatz

Cobalt Strike

Meterpreter
Termite

PsExec



TTPs Matrix (7)
This information is provided by Crocodyli & Ransomware.live
Initial Access Execution Defense Evasion Credential Access Discovery Lateral Movement Command and Control
Valid Accounts: Local Accounts Command and Scripting Interpreter: PowerShell Masquerading: Match Legitimate Name or Location Remote Services: External Remote Services Network Configuration Discovery: Network Connection Enumeration External Remote Services Application Layer Protocol: Web Protocols
External Remote Services Command and Scripting Interpreter: Windows Command Shell Exploitation for Privilege Escalation Exploitation for Credential Access Remote System Discovery Tool Transfer Application Layer Protocol: DNS
  Native API     Process Discovery   Multi-hop Proxy
  User Execution: Malicious File     File and Directory Discovery   Remote Desktop Protocol
  System Services: Service Execution     Time Discovery    
        Network Share Discovery    

YARA Rules (1)

Indicators of Compromise (IoCs) (3)
Email 3
Type IOC
Email admin@cuba-supp.com
Email cuba_support@exploit.im
Email roselondon@cock.li

Victims (103)
Logo
Discovered: 2024-02-01 (2y ago)
DMS is a French industrial company specialized in digital radiology, with an international reach, an…
Logo
Discovered: 2024-01-22 (2y ago)  ·  Attack est.: 2024-01-18
Our teamOur team in Deerlijk consists of enthusiastic and motivated people with passion for their pr…
Logo
Discovered: 2023-11-14 (2y ago)
HistoryEstablished in 1987, DiagnosTechs was the first laboratory to introduce saliva hormone testin…
Logo
Discovered: 2023-11-13 (2y ago)
PORT ADELAIDE is renowned for setting the bar high and expecting success, and the club’s latest stra…
Logo
Discovered: 2023-11-07 (2y ago)
About PANAYAPanaya’s Change Intelligence solutions reduce the time, cost, and risk involved in chang…
Logo
Discovered: 2023-11-07 (2y ago)
For PAJ, your success is our success.Jewelry making is an art and a science. We are constantly impro…
Logo
Discovered: 2023-10-23 (2y ago)
FROM A SINGLE START-UP TO A MULTI-MILLION DOLLAR COMPANYOur prosperity is due to three interlocking …
Logo
Discovered: 2023-10-10 (2y ago)
Mount St Mary’s is rightly proud of its extensive heritage dating back over 160 years. The original …
Logo
Discovered: 2023-10-03 (2y ago)
Rock County Public Health DepartmentThe Rock County Public Health Department (RCPHD) is a level III …
Logo
Discovered: 2023-08-19 (2y ago)
Gold Medal Bakery aspires to follow three core values in every aspect of its business.Integrity: Gol…
Logo
Discovered: 2023-07-31 (2y ago)
Established in 1985, with 13 depots and one support centre nationwide, Hydrex is one of the largest …
Logo
Discovered: 2023-07-31 (2y ago)
At TXM Plant we know that the services we provide are critical to the success of our customers’ proj…
Logo
Discovered: 2023-07-11 (2y ago)
More than 36,000 people call the Village of Addison home.  Whether you are new to our community, or …
Logo
Discovered: 2023-05-23 (2y ago)
About The Philadelphia Inquirer, PBCSince 1829, The Philadelphia Inquirer has been “asking on behalf…
Logo
Discovered: 2023-05-10 (3y ago)
Užtikrindami oruma darbe mes užtikriname ir pamatines žmogaus teisesValstybines darbo inspekcijos (V…
Logo
Discovered: 2023-05-04 (3y ago)
Your health is our top priority. We specialize in digestive system care and will guide you through e…
Logo
Discovered: 2022-12-27 (3y ago)
Phoenicia University (PU) is a non-profit, private, and nonsectarian officially licensed institution…
Logo
Discovered: 2022-12-20 (3y ago)
From yarn-production through its fabric mills that draw on in new innovation and technology, to reta…
Logo
Discovered: 2022-12-12 (3y ago)
No description available
Logo
Discovered: 2022-12-01 (3y ago)
No description available
Logo
Discovered: 2022-12-01 (3y ago)
No description available
Logo
Discovered: 2022-12-01 (3y ago)
No description available
Logo
Discovered: 2022-11-30 (3y ago)
No description available
Logo
Discovered: 2022-11-24 (3y ago)
No description available
Logo
Discovered: 2022-11-09 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-11-04 (3y ago)
No description available
Logo
Discovered: 2022-09-27 (3y ago)
No description available
Logo
Discovered: 2022-08-30 (3y ago)
No description available
Logo
Discovered: 2022-07-21 (3y ago)
No description available
Logo
Discovered: 2022-07-07 (3y ago)
No description available
Logo
Discovered: 2022-06-27 (3y ago)
No description available
Logo
Discovered: 2022-06-13 (3y ago)
No description available
Logo
Discovered: 2022-05-17 (3y ago)
No description available
Logo
Discovered: 2022-05-16 (3y ago)
No description available
Logo
Discovered: 2022-04-22 (4y ago)
No description available
Logo
Discovered: 2022-04-22 (4y ago)
No description available
Logo
Discovered: 2022-04-12 (4y ago)
No description available
Logo
Discovered: 2022-04-08 (4y ago)
No description available
Logo
Discovered: 2022-03-30 (4y ago)
No description available
Logo
Discovered: 2022-03-30 (4y ago)
No description available
Logo
Discovered: 2022-03-23 (4y ago)
No description available
Logo
Discovered: 2022-03-23 (4y ago)
No description available
Logo
Discovered: 2022-02-25 (4y ago)
No description available
Logo
Discovered: 2022-02-18 (4y ago)
No description available
Logo
Discovered: 2022-02-18 (4y ago)
No description available
Logo
Discovered: 2022-02-04 (4y ago)
No description available
Logo
Discovered: 2022-02-04 (4y ago)
No description available
Logo
Discovered: 2022-02-04 (4y ago)
No description available
Logo
Discovered: 2022-01-25 (4y ago)
No description available
Logo
Discovered: 2022-01-13 (4y ago)
No description available
Logo
Discovered: 2022-01-13 (4y ago)
No description available
Logo
Discovered: 2022-01-10 (4y ago)
No description available
Logo
Discovered: 2022-01-10 (4y ago)
No description available
Logo
Discovered: 2022-01-10 (4y ago)
No description available
Logo
Discovered: 2022-01-10 (4y ago)
No description available
Logo
Discovered: 2022-01-10 (4y ago)
No description available
Logo
Discovered: 2021-12-30 (4y ago)
No description available
Logo
Discovered: 2021-12-30 (4y ago)
No description available
Logo
Discovered: 2021-12-30 (4y ago)
No description available
Logo
Discovered: 2021-12-30 (4y ago)
No description available
Logo
Discovered: 2021-12-30 (4y ago)
No description available
Logo
Discovered: 2021-12-30 (4y ago)
No description available
Logo
Discovered: 2021-09-09 (4y ago)
No description available