logo

McAfee ATR Threat Report: A Quick Primer on Cuba Ransomware

ID: 1810c860-4852-58e5-b02b-0b2f40d8fb16

STIX ID: report--1810c860-4852-58e5-b02b-0b2f40d8fb16

Feed Name: McAfee Labs Blog

Threat Score
75/100

Date Published: 2021-04-06

Date Updated: 2026-04-28

Author: Thomas Roccia

...
...

Cuba ransomware has evolved into an active Ransomware-as-a-Service campaign that combines file encryption with data exfiltration and a public leak site; actors use obfuscated PowerShell scripts for lateral movement, leverage/common pentest tools and frameworks (e.g., winPEAS, Bloodhound, Cobalt Strike), and target financial, industry, technology, and logistics organizations. The report provides YARA rules, IOCs, MITRE ATT&CK mappings and defensive guidance such as monitoring for dual‑use tool abuse, hardening RDP and credentials, patching public‑facing apps, and strengthening endpoint protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.