Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business

Cuba

The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted.

Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site.

According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in 2023, there were indications that the developer behind the Cuba ransomware speaks Russian.

The ransomware operators use a double extortion approach, and following the USA, in August 2022, it was believed that the Cuba ransomware group had compromised 101 entities, demanding $145 million in ransom payments and receiving up to $60 million.

The group used a similar set of TTPs, with only a slight change each year, as they generally consist of LOLBins (executables that are part of the operating system and can be exploited to support an attack), exploits, off-the-shelf and custom malware, as well as intrusion tools like Cobalt Strike and Metasploit.

In 2022, the group allegedly developed a relationship with operators of the Industrial Spy market, using their platform as a means of data leakage.
Source: https://github.com/crocodyli/ThreatActors-TTPs
External information

Victims
 

105

First Discovered
victim

2021-02-03

Last Discovered
victim

2024-02-01

Avg Delay
between attack and claim

4 days

Infostealer
for victim with domain

0.0%

View Victims on World Map


Known Locations (2)
Favicon Title Type Available Last Visit FQDN
favicon None No 2025-06-01 21:18:24 cuba4mp6ximo2zlo.onion
favicon Cuba No 2025-06-01 21:18:32 cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion

Target (Available)
Top 5 Activity Sectors
  • Financial 1
  • Manufacturing 1
  • Healthcare 1
Top 5 Countries
  • GB flag United Kingdom 3
  • US flag United States 2
  • BE flag Belgium 1
  • FR flag France 1

Heatmap (Available)

Ransom Notes (1)

Tools Used (Available)
This information is provided by Ransomware-Tool-Matrix
Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration

NetSupport

Avast Anti-Rootkit driver

Mimikatz

Cobalt Strike

Meterpreter
Termite

PsExec



Vulnerabilities Exploited (0)

No vulnerabilities exploited available.


TTPs Matrix (7)
This information is provided by Crocodyli & Ransomware.live
Initial Access Execution Defense Evasion Discovery Lateral Movement Credential Access Command and Control
External Remote Services Native API Masquerading: Match Legitimate Name or Location Time Discovery Tool Transfer Exploitation for Credential Access Remote Desktop Protocol
Valid Accounts: Local Accounts User Execution: Malicious File Exploitation for Privilege Escalation Network Share Discovery External Remote Services Remote Services: External Remote Services Multi-hop Proxy
  Command and Scripting Interpreter: PowerShell   Remote System Discovery     Application Layer Protocol: DNS
  Command and Scripting Interpreter: Windows Command Shell   File and Directory Discovery     Application Layer Protocol: Web Protocols
  System Services: Service Execution   Process Discovery      
      Network Configuration Discovery: Network Connection Enumeration      

Negotiation Chats (0)

No negotiation chats available.


YARA Rules (0)

No YARA rules available.


Indicators of Compromise (IoCs) (0)

No IoCs available for this group.


Victims (105)
Logo
dms-imaging Cuba
Discovery Date: 2024-02-01
DMS is a French industrial company specialized in digital radiology, with an international reach, an...
FR
Logo
deknudtframes.be Cuba
Discovery Date: 2024-01-22
Estimated Attack Date: 2024-01-18
Our teamOur team in Deerlijk consists of enthusiastic and motivated people with passion for their pr...
BE
Logo
diagnostechs Cuba
Discovery Date: 2023-11-14
HistoryEstablished in 1987, DiagnosTechs was the first laboratory to introduce saliva hormone testin...
Logo
portadelaidefc Cuba
Discovery Date: 2023-11-13
PORT ADELAIDE is renowned for setting the bar high and expecting success, and the club’s latest stra...
Logo
panaya Cuba
Discovery Date: 2023-11-07
About PANAYAPanaya’s Change Intelligence solutions reduce the time, cost, and risk involved in chang...
Logo
prime-art Cuba
Discovery Date: 2023-11-07
For PAJ, your success is our success.Jewelry making is an art and a science. We are constantly impro...
Logo
Newconcepttech Cuba
Discovery Date: 2023-10-23
FROM A SINGLE START-UP TO A MULTI-MILLION DOLLAR COMPANYOur prosperity is due to three interlocking ...
Logo
mountstmarys Cuba
Discovery Date: 2023-10-10
Mount St Mary’s is rightly proud of its extensive heritage dating back over 160 years. The original ...
Logo
co.rock.wi.us Cuba
Discovery Date: 2023-10-03
Rock County Public Health DepartmentThe Rock County Public Health Department (RCPHD) is a level III ...
US
Logo
goldmedalbakery Cuba
Discovery Date: 2023-08-19
Gold Medal Bakery aspires to follow three core values in every aspect of its business.Integrity: Gol...
Logo
hydrex.co.uk Cuba
Discovery Date: 2023-07-31
Established in 1985, with 13 depots and one support centre nationwide, Hydrex is one of the largest ...
GB
Logo
txmplant.co.uk Cuba
Discovery Date: 2023-07-31
At TXM Plant we know that the services we provide are critical to the success of our customers’ proj...
GB
Logo
gis4.addison-il Cuba
Discovery Date: 2023-07-11
More than 36,000 people call the Village of Addison home.  Whether you are new to our community, or ...
Logo
Inquirer Cuba
Discovery Date: 2023-05-23
About The Philadelphia Inquirer, PBCSince 1829, The Philadelphia Inquirer has been “asking on behalf...
Logo
Vdi Cuba
Discovery Date: 2023-05-10
Užtikrindami oruma darbe mes užtikriname ir pamatines žmogaus teisesValstybines darbo inspekcijos (V...
Logo
Gihealthcare Cuba
Discovery Date: 2023-05-04
Your health is our top priority. We specialize in digestive system care and will guide you through e...
Logo
pu.edu.lb Cuba
Discovery Date: 2022-12-27
Phoenicia University (PU) is a non-profit, private, and nonsectarian officially licensed institution...
Logo
Sae-a Cuba
Discovery Date: 2022-12-20
From yarn-production through its fabric mills that draw on in new innovation and technology, to reta...
Logo
2networkit Cuba
Discovery Date: 2022-12-12
N/A
Logo
Landaumedia Cuba
Discovery Date: 2022-12-01
N/A
Logo
Generator-power Cuba
Discovery Date: 2022-12-01
N/A
Logo
Boss-inc Cuba
Discovery Date: 2022-12-01
N/A
Logo
Patton Cuba
Discovery Date: 2022-11-30
N/A
Logo
Pmc-group Cuba
Discovery Date: 2022-11-24
N/A
Logo
waltersandwolf Cuba
Discovery Date: 2022-11-09
N/A
Logo
bfw Cuba
Discovery Date: 2022-11-04
N/A
Logo
Ville-chaville Cuba
Discovery Date: 2022-11-04
N/A
Logo
Murphyfamilyventures Cuba
Discovery Date: 2022-11-04
N/A
Logo
Ginspectionservices Cuba
Discovery Date: 2022-11-04
N/A
Logo
Dialogsas Cuba
Discovery Date: 2022-11-04
N/A
Logo
usairports Cuba
Discovery Date: 2022-11-04
N/A
Logo
trant.co.uk Cuba
Discovery Date: 2022-11-04
N/A
GB
Logo
the_rose_executive_team Cuba
Discovery Date: 2022-11-04
N/A
Logo
technicote Cuba
Discovery Date: 2022-11-04
N/A
Logo
stm.com.tw Cuba
Discovery Date: 2022-11-04
N/A
Logo
site-technology_ Cuba
Discovery Date: 2022-11-04
N/A
Logo
schultheis-ins Cuba
Discovery Date: 2022-11-04
N/A
Logo
quercus Cuba
Discovery Date: 2022-11-04
N/A
Logo
otrcapital Cuba
Discovery Date: 2022-11-04
N/A
Logo
ohagin Cuba
Discovery Date: 2022-11-04
N/A
Logo
nwdusa Cuba
Discovery Date: 2022-11-04
N/A
Logo
ncmutuallife2 Cuba
Discovery Date: 2022-11-04
N/A
Logo
meriplex Cuba
Discovery Date: 2022-11-04
N/A
Logo
megaforce Cuba
Discovery Date: 2022-11-04
N/A
Logo
lycra Cuba
Discovery Date: 2022-11-04
N/A
Logo
linkmfg Cuba
Discovery Date: 2022-11-04
N/A
Logo
learning_resources Cuba
Discovery Date: 2022-11-04
N/A
Logo
landofrost Cuba
Discovery Date: 2022-11-04
N/A
Logo
innovairre Cuba
Discovery Date: 2022-11-04
N/A
Logo
get-integrated Cuba
Discovery Date: 2022-11-04
N/A
Logo
gascaribe Cuba
Discovery Date: 2022-11-04
N/A
Logo
forefront_dermatology Cuba
Discovery Date: 2022-11-04
N/A
Logo
first_coast_logistics_services Cuba
Discovery Date: 2022-11-04
N/A
Logo
e.h._wachs_pipe_cutters Cuba
Discovery Date: 2022-11-04
N/A
Logo
datamatics Cuba
Discovery Date: 2022-11-04
N/A
Logo
creditriskmonitor Cuba
Discovery Date: 2022-11-04
N/A
Logo
blackhawk Cuba
Discovery Date: 2022-11-04
N/A
Logo
berding-weil Cuba
Discovery Date: 2022-11-04
N/A
Logo
bcintlgroup.com Cuba
Discovery Date: 2022-11-04
N/A
Logo
axley Cuba
Discovery Date: 2022-11-04
N/A
Logo
afts Cuba
Discovery Date: 2022-11-04
N/A
Logo
Skupstina Cuba
Discovery Date: 2022-11-04
N/A
Logo
ginspectionservices Cuba
Discovery Date: 2022-09-27
N/A
Logo
skupstina Cuba
Discovery Date: 2022-08-30
N/A
Logo
site-technology Cuba
Discovery Date: 2022-07-21
N/A
Logo
stm-com-tw Cuba
Discovery Date: 2022-07-07
N/A
Logo
r1group Cuba
Discovery Date: 2022-06-27
N/A
Logo
etron Cuba
Discovery Date: 2022-06-13
N/A
Logo
upskwt Cuba
Discovery Date: 2022-05-17
N/A
Logo
fronteousa Cuba
Discovery Date: 2022-05-16
N/A
Logo
prophoenix Cuba
Discovery Date: 2022-04-22
N/A
Logo
metrobrokers Cuba
Discovery Date: 2022-04-22
N/A
Logo
tavistock Cuba
Discovery Date: 2022-04-12
N/A
Logo
metagenics Cuba
Discovery Date: 2022-04-08
N/A
Logo
bcintlgroup-com Cuba
Discovery Date: 2022-03-30
N/A
Logo
trant-co-uk Cuba
Discovery Date: 2022-03-30
N/A
Logo
haltonhills Cuba
Discovery Date: 2022-03-23
N/A
Logo
powertech Cuba
Discovery Date: 2022-03-23
N/A
Logo
ids97 Cuba
Discovery Date: 2022-02-25
N/A
Logo
muntons Cuba
Discovery Date: 2022-02-18
N/A
Logo
heritage-encon Cuba
Discovery Date: 2022-02-18
N/A
Logo
shoesforcrews Cuba
Discovery Date: 2022-02-04
N/A
Logo
edgo Cuba
Discovery Date: 2022-02-04
N/A
Logo
cmmcpas Cuba
Discovery Date: 2022-02-04
N/A
Logo
mtlcraft Cuba
Discovery Date: 2022-01-25
N/A
Logo
superfund Cuba
Discovery Date: 2022-01-13
N/A
Logo
fdcbuilding Cuba
Discovery Date: 2022-01-13
N/A
Logo
strongwell Cuba
Discovery Date: 2022-01-10
N/A
Logo
sonomatic-2 Cuba
Discovery Date: 2022-01-10
N/A
Logo
regulvar Cuba
Discovery Date: 2022-01-10
N/A
Logo
delinebox Cuba
Discovery Date: 2022-01-10
N/A
Logo
cle Cuba
Discovery Date: 2022-01-10
N/A
Logo
squamish Cuba
Discovery Date: 2021-12-30
N/A
Logo
sonomatic Cuba
Discovery Date: 2021-12-30
N/A
Logo
ncmutuallife Cuba
Discovery Date: 2021-12-30
N/A
Logo
lahebert Cuba
Discovery Date: 2021-12-30
N/A
Logo
bakertilly Cuba
Discovery Date: 2021-12-30
N/A
Logo
atlasdie Cuba
Discovery Date: 2021-12-30
N/A
Logo
Rose Associates Mission Statement Cuba
Discovery Date: 2021-09-09
N/A