logo

CUBA Ransomware Campaign Analysis

ID: 3fbfbb4b-7325-5cd6-8de9-bc7f6050ae50

STIX ID: report--3fbfbb4b-7325-5cd6-8de9-bc7f6050ae50

Feed Name: Elastic Security Labs

Threat Score
78/100

Date Published: 2022-09-08

Date Updated: 2026-04-27

...
...

Elastic Security provides a technical analysis of Cuba ransomware activity used by a financially motivated actor targeting small and medium retailers and manufacturers in North America and Europe: the report documents initial access (Exchange/ProxyLogon and possible access brokers), payloads and droppers (afk.ttf, add2.exe, Agent32/BUGHATCH), post-exploitation tooling (SystemBC, NetSupport, GoToAssist, Cobalt Strike, Meterpreter, Mimikatz), credential theft, lateral movement (Zerologon, PsExec, LOLBAS), data exfiltration and extortion, and supplies YARA rules, IOCs, and defensive recommendations including patching, memory protections, backups, and segmentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.