Ransomware Group:  
Cuba



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Sites | External Information | Tools | TTPs | Ransom Note(s) | Activity | Worldmap | Victims (105)

The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted.

Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site.

According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in 2023, there were indications that the developer behind the Cuba ransomware speaks Russian.

The ransomware operators use a double extortion approach, and following the USA, in August 2022, it was believed that the Cuba ransomware group had compromised 101 entities, demanding $145 million in ransom payments and receiving up to $60 million.

The group used a similar set of TTPs, with only a slight change each year, as they generally consist of LOLBins (executables that are part of the operating system and can be exploited to support an attack), exploits, off-the-shelf and custom malware, as well as intrusion tools like Cobalt Strike and Metasploit.

In 2022, the group allegedly developed a relationship with operators of the Industrial Spy market, using their platform as a means of data leakage.
Source: https://github.com/crocodyli/ThreatActors-TTPs


Sites

Title Available Last Visit FQDN Screenshot
None 🔴 2021-05-01 00:00:00.000000 cuba4mp6ximo2zlo.onion N/A
Cuba 🔴 2024-02-08 10:44:35.656037 cuba4ikm4jakjgmkezytyawtdgr2xymvy6nvzgw5cglswg3si76icnqd.onion N/A

External information

Tools used

Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
NetSupport Avast Anti-Rootkit driver Mimikatz Cobalt Strike Termite PsExec
Meterpreter

This information is provided by Ransomware-Tool-Matrix

TTPs

Ransom Note(s)

Activity over time

Worldmap

105 Victims

FR flag

dms-imaging 

Company logo
Ransomware Group:

Discovery Date: 2024-02-01 16:34

Sector: Healthcare
DMS is a French industrial company specialized in digital radiology, with an international reach, and recognized as a key actor and an indispensable partner in creating value through the quality of our solutions as well as our...

Victim:   |  Group: 
BE flag

deknudtframes.be 

Company logo
Ransomware Group:

Discovery Date: 2024-01-22 10:22
Estimated Attack Date: 2024-01-18

Our teamOur team in Deerlijk consists of enthusiastic and motivated people with passion for their profession. The management, sales, logistics, purchasing, accounting, customer service and marketing are ready for you on a daily...

Victim:   |  Group: 
 flag

diagnostechs 

Company logo
Ransomware Group:

Discovery Date: 2023-11-14 11:26

Sector:
HistoryEstablished in 1987, DiagnosTechs was the first laboratory to introduce saliva hormone testing into routine clinical practice. In 1995, DiagnosTechs added saliva and stool-based gastrointestinal and food sensitivity testing,...

Victim:   |  Group: 
 flag

portadelaidefc 

Company logo
Ransomware Group:

Discovery Date: 2023-11-13 18:57

Sector:
PORT ADELAIDE is renowned for setting the bar high and expecting success, and the club’s latest strategic vision embraces that expectation.Unveiled at the club’s Annual General Meeting on Friday night, Chasing Greatness is...

Victim:   |  Group: 
 flag

panaya 

Company logo
Ransomware Group:

Discovery Date: 2023-11-07 08:33

Sector:
About PANAYAPanaya’s Change Intelligence solutions reduce the time, cost, and risk involved in change to business applications like SAP®, Oracle® EBS, and Salesforce.com. Date the files were received:  02...

Victim:   |  Group: 
 flag

prime-art 

Company logo
Ransomware Group:

Discovery Date: 2023-11-07 08:33

Sector:
For PAJ, your success is our success.Jewelry making is an art and a science. We are constantly improving and optimizing our skills while integrating cutting-edge technology.By always delivering a troy grain more than anticipated, we...

Group: 
 flag

Newconcepttech 

Company logo
Ransomware Group:

Discovery Date: 2023-10-23 19:06

Sector:
FROM A SINGLE START-UP TO A MULTI-MILLION DOLLAR COMPANYOur prosperity is due to three interlocking factors: the first, being our customers, who have always come first.The second, our employees, who are passionate about serving our...

Group: 
 flag

mountstmarys 

Company logo
Ransomware Group:

Discovery Date: 2023-10-10 11:37

Sector:
Mount St Mary’s is rightly proud of its extensive heritage dating back over 160 years. The original vision to educate all young people in the local area remains at the core of our work. Our mission is to ensure individual...

Group: 
US flag

co.rock.wi.us 

Company logo
Ransomware Group:

Discovery Date: 2023-10-03 10:03

Sector:
Rock County Public Health DepartmentThe Rock County Public Health Department (RCPHD) is a level III health department in Rock County, Wisconsin. Our staff serves over 160,000 people in more than 25 cities, villages, and towns. As a...

Victim:   |  Group: 
 flag

goldmedalbakery 

Company logo
Ransomware Group:

Discovery Date: 2023-08-19 16:02

Sector:
Gold Medal Bakery aspires to follow three core values in every aspect of its business.Integrity: Gold Medal has built its reputation on meeting the needs of our customers and the millions of consumers they serve. Thus, integrity is...

Victim:   |  Group: 
GB flag

hydrex.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2023-07-31 12:54

Sector:
Established in 1985, with 13 depots and one support centre nationwide, Hydrex is one of the largest suppliers of outsourced mobile plant solutions in the UK.Hydrex has a fleet totaling over 1200 machines. The company has invested in...

Victim:   |  Group: 
GB flag

txmplant.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2023-07-31 12:54

Sector:
At TXM Plant we know that the services we provide are critical to the success of our customers’ projects. That’s why we put the customer at the centre of everything that we do.Awarded ‘Gold’ standard in Network...

Victim:   |  Group: 
 flag

gis4.addison-il 

Company logo
Ransomware Group:

Discovery Date: 2023-07-11 08:51

Sector:
More than 36,000 people call the Village of Addison home.  Whether you are new to our community, or have lived here for years, we want you to get acquainted with our community. We also want to make it easy for you to stay...

Victim:   |  Group: 
 flag

Inquirer 

Company logo
Ransomware Group:

Discovery Date: 2023-05-23 08:52

Sector:
About The Philadelphia Inquirer, PBCSince 1829, The Philadelphia Inquirer has been “asking on behalf of the people” of Philadelphia and the region by providing essential journalism. Locally owned and headquartered in...

Victim:   |  Group: 
 flag

Vdi 

Company logo
Ransomware Group:

Discovery Date: 2023-05-10 13:47

Sector:
Užtikrindami oruma darbe mes užtikriname ir pamatines žmogaus teisesValstybines darbo inspekcijos (VDI) misija – orus darbas. Spalio 7-aja minint Diena už oru darba VDI primena, kad tarpusavio pagarba ir saugumas darbe saugo...

Victim:   |  Group: 
 flag

Gihealthcare 

Company logo
Ransomware Group:

Discovery Date: 2023-05-04 08:49

Sector:
Your health is our top priority. We specialize in digestive system care and will guide you through every step – whether it’s a routine colon screening, major liver or pancreas issue, or a weight loss journey. With three...

Victim:   |  Group: 
 flag

pu.edu.lb 

Company logo
Ransomware Group:

Discovery Date: 2022-12-27 12:31

Sector:
Phoenicia University (PU) is a non-profit, private, and nonsectarian officially licensed institution of higher education. The University comprises six colleges: Architecture and Design, Arts and Sciences, Business, Engineering, Law...

Group: 
 flag

Sae-a 

Company logo
Ransomware Group:

Discovery Date: 2022-12-20 13:10

Sector:
From yarn-production through its fabric mills that draw on in new innovation and technology, to retail operations in Korea, SAE-A has become one of the few apparel manufacturers capable of achieving complete vertical-integration of...

Group: 
 flag

2networkit 

Company logo
Ransomware Group:

Discovery Date: 2022-12-12 09:25

Sector:

Group: 
 flag

Landaumedia 

Company logo
Ransomware Group:

Discovery Date: 2022-12-01 14:25

Sector:

Group: 
 flag

Generator-power 

Company logo
Ransomware Group:

Discovery Date: 2022-12-01 14:25

Sector:

Group: 
 flag

Boss-inc 

Company logo
Ransomware Group:

Discovery Date: 2022-12-01 14:25

Sector:

Group: 
 flag

Patton 

Company logo
Ransomware Group:

Discovery Date: 2022-11-30 14:30

Sector:

Group: 
 flag

Pmc-group 

Company logo
Ransomware Group:

Discovery Date: 2022-11-24 15:03

Sector:

Group: 
 flag

waltersandwolf 

Company logo
Ransomware Group:

Discovery Date: 2022-11-09 09:26

Sector:

Group: 
 flag

bfw 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 17:45

Sector:

Group: 
 flag

Ville-chaville 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 17:45

Sector:

Group: 
 flag

Murphyfamilyventures 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 17:45

Sector:

Group: 
 flag

Ginspectionservices 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 17:45

Sector:

Group: 
 flag

Dialogsas 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 17:45

Sector:

Group: 
 flag

usairports 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
GB flag

trant.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

the_rose_executive_team 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

technicote 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

stm.com.tw 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

site-technology_ 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

schultheis-ins 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

quercus 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

otrcapital 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

ohagin 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

nwdusa 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

ncmutuallife2 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

meriplex 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

megaforce 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

lycra 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

linkmfg 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

learning_resources 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

landofrost 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

innovairre 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

get-integrated 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

gascaribe 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

forefront_dermatology 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

first_coast_logistics_services 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

e.h._wachs_pipe_cutters 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

datamatics 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

creditriskmonitor 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

blackhawk 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

berding-weil 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

bcintlgroup.com 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

axley 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

afts 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

Skupstina 

Company logo
Ransomware Group:

Discovery Date: 2022-11-04 10:19

Sector:

Group: 
 flag

ginspectionservices 

Company logo
Ransomware Group:

Discovery Date: 2022-09-27 11:11

Sector:

Group: 
 flag

skupstina 

Company logo
Ransomware Group:

Discovery Date: 2022-08-30 12:51

Sector:

Group: 
 flag

site-technology 

Company logo
Ransomware Group:

Discovery Date: 2022-07-21 12:57

Sector:

Group: 
 flag

stm-com-tw 

Company logo
Ransomware Group:

Discovery Date: 2022-07-07 10:24

Sector:

Group: 
 flag

r1group 

Company logo
Ransomware Group:

Discovery Date: 2022-06-27 11:53

Sector:

Group: 
 flag

etron 

Company logo
Ransomware Group:

Discovery Date: 2022-06-13 18:03

Sector:

Group: 
 flag

upskwt 

Company logo
Ransomware Group:

Discovery Date: 2022-05-17 15:30

Sector:

Group: 
 flag

fronteousa 

Company logo
Ransomware Group:

Discovery Date: 2022-05-16 10:29

Sector:

Group: 
 flag

prophoenix 

Company logo
Ransomware Group:

Discovery Date: 2022-04-22 15:27

Sector:

Group: 
 flag

metrobrokers 

Company logo
Ransomware Group:

Discovery Date: 2022-04-22 14:38

Sector:

Group: 
 flag

tavistock 

Company logo
Ransomware Group:

Discovery Date: 2022-04-12 09:24

Sector:

Group: 
 flag

metagenics 

Company logo
Ransomware Group:

Discovery Date: 2022-04-08 11:20

Sector:

Group: 
 flag

bcintlgroup-com 

Company logo
Ransomware Group:

Discovery Date: 2022-03-30 10:20

Sector:

Group: 
 flag

trant-co-uk 

Company logo
Ransomware Group:

Discovery Date: 2022-03-30 08:23

Sector:

Group: 
 flag

haltonhills 

Company logo
Ransomware Group:

Discovery Date: 2022-03-23 18:27

Sector:

Group: 
 flag

powertech 

Company logo
Ransomware Group:

Discovery Date: 2022-03-23 10:33

Sector:

Group: 
 flag

ids97 

Company logo
Ransomware Group:

Discovery Date: 2022-02-25 17:30

Sector:

Group: 
 flag

muntons 

Company logo
Ransomware Group:

Discovery Date: 2022-02-18 18:25

Sector:

Group: 
 flag

heritage-encon 

Company logo
Ransomware Group:

Discovery Date: 2022-02-18 18:25

Sector:

Group: 
 flag

shoesforcrews 

Company logo
Ransomware Group:

Discovery Date: 2022-02-04 09:20

Sector:

Group: 
 flag

edgo 

Company logo
Ransomware Group:

Discovery Date: 2022-02-04 09:20

Sector:

Group: 
 flag

cmmcpas 

Company logo
Ransomware Group:

Discovery Date: 2022-02-04 09:20

Sector:

Group: 
 flag

mtlcraft 

Company logo
Ransomware Group:

Discovery Date: 2022-01-25 08:29

Sector:

Group: 
 flag

superfund 

Company logo
Ransomware Group:

Discovery Date: 2022-01-13 13:27

Sector:

Group: 
 flag

fdcbuilding 

Company logo
Ransomware Group:

Discovery Date: 2022-01-13 09:22

Sector:

Group: 
 flag

strongwell 

Company logo
Ransomware Group:

Discovery Date: 2022-01-10 10:22

Sector:

Group: 
 flag

sonomatic-2 

Company logo
Ransomware Group:

Discovery Date: 2022-01-10 10:22

Sector:

Group: 
 flag

regulvar 

Company logo
Ransomware Group:

Discovery Date: 2022-01-10 10:22

Sector:

Group: 
 flag

delinebox 

Company logo
Ransomware Group:

Discovery Date: 2022-01-10 10:22

Sector:

Group: 
 flag

cle 

Company logo
Ransomware Group:

Discovery Date: 2022-01-10 10:22

Sector:

Group: 
 flag

squamish 

Company logo
Ransomware Group:

Discovery Date: 2021-12-30 01:51

Sector:

Group: 
 flag

sonomatic 

Company logo
Ransomware Group:

Discovery Date: 2021-12-30 01:51

Sector:

Group: 
 flag

ncmutuallife 

Company logo
Ransomware Group:

Discovery Date: 2021-12-30 01:51

Sector:

Group: 
 flag

lahebert 

Company logo
Ransomware Group:

Discovery Date: 2021-12-30 01:51

Sector:

Group: 
 flag

bakertilly 

Company logo
Ransomware Group:

Discovery Date: 2021-12-30 01:51

Sector:

Group: 
 flag

atlasdie 

Company logo
Ransomware Group:

Discovery Date: 2021-12-30 01:51

Sector:

Group: 
 flag

The Squamish Nation is comprised of descendants of the Coast Salish Aboriginal peoples who 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

First Coast Logistics Services, Inc. was founded in 1999. The Company's line of business i 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Datamatics is a technology company that builds intelligent solutions enabling data-driven 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

Rose Associates Mission Statement 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

AFTS supplies the preeminent Payment Processing, IRS 1031 Exchange, Data Processing, Invoi 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
 flag

OTR Capital believes in simple and straightforward transactions, without hidden costs and 

Company logo
Ransomware Group:

Discovery Date: 2021-09-09 23:46

Sector:

Group: 
US flag

Automatic Funds Transfer Services Inc. (vendor to city of Bainbridge Island) 

Company logo
Ransomware Group:

Discovery Date: 2021-02-03 00:00

Group: