cuba logo

cuba

1 incidentes 1 paises 0 sectores ransomware RU Ultimo: 2026-06-25
Aliases: Tropical Scorpius, Fidel, COLDDRAW
Ver en IntelTracker → APTTrail →
Cuba is a financially motivated ransomware-as-a-service (RaaS) operation that first emerged in December 2019. Despite its name, the group has no known ties to the Republic of Cuba and is strongly assessed to be of Russian origin, indicated by language artifacts and its ransomware's self-termination on systems with Russian language settings. The group employs a double extortion model, encrypting victim data and threatening to publicly leak exfiltrated sensitive information if ransom demands are not met. By August 2022, Cuba had reportedly compromised over 100 entities worldwide, demanding more than $145 million and receiving approximately $60 million in ransom payments. The group continuously evolves its tactics, techniques, and procedures, operating under various aliases including ColdDraw, Tropical Scorpius, and Fidel.
Malware asociado
Turla, Arkei, Turla, win.emotet, GhostLocker
Tecnicas MITRE
T1574 - Hijack Execution Flow, T1027 - Obfuscated Files or Information, T1189 - Drive-by Compromise, T1036 - Masquerading, T1090 - Proxy, T1547 - Boot or Logon Autostart Execution
CVEs relacionadas
CVE-2023-47246, CVE-2023-46850, CVE-2023-46849, CVE-2023-46747, CVE-2023-46604, CVE-2023-36884

RansomLook pivots

Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.

Abrir perfil →
Data
RecentBrowseTrendingStats
Intel
GroupURLsCryptoLeaksNotesAnalysesTorrents
Info
APIGlossaryAbout
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

United Arab EmiratesArgentinaAmerican SamoaAustriaAustraliaAzerbaijanBelgiumBrazilCanadaSwitzerland

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankCredit UnionsSoftware PublishersReal EstateHospitalsAccommodationAir Transportation

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com