Description
Cuba is a Windows based ransomware family used against financial institutions, technology, and logistics organizations in North and South America as well as Europe since at least December 2019.
Stats
- First seen
- February 2022
- Last seen
- October 2026
MITRE ATT&CK techniques
23 techniques across 7 tactics.
TA0002 Execution
TA0005 Stealth
- T1027Obfuscated Files or Information
- T1027.002Software Packing
- T1027Obfuscated Files or Information
- T1027.002Software Packing
- T1036Masquerading
- T1036.005Match Legitimate Resource Name or Location
- T1070Indicator Removal
- T1070.004File Deletion
- T1134Access Token Manipulation
- T1564Hide Artifacts
- T1564.003Hidden Window
- T1620Reflective Code Loading
TA0007 Discovery
TA0011 Command and Control
- T1105Ingress Tool Transfer
Alert name variants
| Alert Name |
|---|
| DeepScan:Generic.Ransom.Cuba.097204E7 |
| DeepScan:Generic.Ransom.Cuba.4D0E95B0 |
| DeepScan:Generic.Ransom.Cuba.52466964 |
| DeepScan:Generic.Ransom.Cuba.D265BE39 |
| Dump:Generic.Ransom.Cuba.C32CFE13 |
| Gen:Variant.Ransom.Cuba.3 |
| Generic.Ransom.Cuba.097204E7 |
| Generic.Ransom.Cuba.11D2667D |
| Generic.Ransom.Cuba.21BEDDA8 |
| Generic.Ransom.Cuba.D265BE39 |

