cuba
1 incidentes
1 paises
0 sectores
ransomware RU Ultimo: 2026-06-25
Aliases: Tropical Scorpius, Fidel, COLDDRAW
Cuba is a financially motivated ransomware-as-a-service (RaaS) operation that first emerged in December 2019. Despite its name, the group has no known ties to the Republic of Cuba and is strongly assessed to be of Russian origin, indicated by language artifacts and its ransomware's self-termination on systems with Russian language settings. The group employs a double extortion model, encrypting victim data and threatening to publicly leak exfiltrated sensitive information if ransom demands are not met. By August 2022, Cuba had reportedly compromised over 100 entities worldwide, demanding more than $145 million and receiving approximately $60 million in ransom payments. The group continuously evolves its tactics, techniques, and procedures, operating under various aliases including ColdDraw, Tropical Scorpius, and Fidel.
RansomLook pivots
Data, inteligencia y referencias externas para contrastar actividad ransomware del actor.
Abrir perfil →
Paises objetivo (SOCRadar)
United Arab Emirates
ArgentinaAmerican Samoa
Austria
Australia
Azerbaijan
Belgium
Brazil
Canada
Switzerland
Sectores objetivo (SOCRadar)
Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankCredit UnionsSoftware PublishersReal EstateHospitalsAccommodationAir Transportation
URLs nuevas detectadas en IntelTracker