CUBA Ransomware Campaign Analysis
ID: 3fbfbb4b-7325-5cd6-8de9-bc7f6050ae50
STIX ID: report--3fbfbb4b-7325-5cd6-8de9-bc7f6050ae50
Feed Name: Elastic Security Labs
Elastic Security provides a technical analysis of Cuba ransomware activity used by a financially motivated actor targeting small and medium retailers and manufacturers in North America and Europe: the report documents initial access (Exchange/ProxyLogon and possible access brokers), payloads and droppers (afk.ttf, add2.exe, Agent32/BUGHATCH), post-exploitation tooling (SystemBC, NetSupport, GoToAssist, Cobalt Strike, Meterpreter, Mimikatz), credential theft, lateral movement (Zerologon, PsExec, LOLBAS), data exfiltration and extortion, and supplies YARA rules, IOCs, and defensive recommendations including patching, memory protections, backups, and segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
