logo

Connecting the Bots

ID: 2ae4399e-2066-52f8-9578-e314b9438fa1

STIX ID: report--2ae4399e-2066-52f8-9578-e314b9438fa1

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2021-05-07

Date Updated: 2026-04-27

...
...

**Hancitor-to-Cuba ransomware campaign:** Group-IB documents active Hancitor campaigns that drop additional payloads (Cuba ransomware, Ficker stealer, Cobalt Strike, SystemBC) via DocuSign-themed spam and malicious Word macros, details C2 protocol and commands, post-exploitation TTPs (mimikatz, PsExec, RDP, SMB beacons), and notes exfiltration published on a Cuba data-leak site.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.