← All actors

Cuba

Aliases: Cuba ransomware, Cuba ransomware actors

Source profile review date: 2026-06-01

Added to the source registry: 2021-02-03 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

This dossier separates actor-specific source information from general defensive analysis. Recommendations and investigation questions are not additional claims about the actor. Public evidence remains limited where explicitly stated.

Executive summary

Cuba ransomware actors use vulnerabilities, phishing, compromised credentials, RDP and Hancitor-related access to perform data extortion and encryption.

Cuba is relevant because CISA/FBI link the group to concrete initial-access routes, including known vulnerabilities, phishing, compromised credentials and RDP, followed by loaders, RATs, discovery, exfiltration and ransomware impact.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Executive summary

    Cuba ransomware is a financially motivated extortion operation that, according to FBI and CISA, affected multiple critical infrastructure sectors. The profile is practical because initial access often comes from recognisable weaknesses: known vulnerabilities in commercial software, phishing, compromised credentials and legitimate RDP tools.

    The advisory also describes use of Hancitor, a loader that can drop or execute other malware, RATs and ransomware. A Cuba incident therefore does not start at the encryptor, but at the malware and access chain that precedes it.

    The core message is concrete: patching internet-facing software, hardening RDP, MFA on external access and detection of loader/RAT behaviour are directly relevant.

    Group and development

    Cuba ransomware actors have been visible for several years in public advisories and threat reporting. The name refers to the ransomware brand, not necessarily to country attribution.

    The FBI/CISA 2022 update contains additional IOCs and changed TTPs since spring 2022. A profile should therefore not freeze on one loader or one hash set, but keep describing the chain.

    Cuba is especially relevant for organisations with legacy software, external access and weak patch discipline. The named access routes are common in many networks.

    Attack pattern from public cases

    CISA says Cuba actors used known vulnerabilities in commercial software, phishing campaigns, compromised credentials and legitimate RDP tools for initial access.

    After access, Cuba ransomware was distributed through Hancitor. Hancitor matters because it acts as a loader and can bring in other malware, including RATs and stealers.

    Later phases include discovery, privilege use, lateral movement and data movement. Watch remote desktop activity, new services, unknown admin logins, data compression and outbound traffic.

    Cuba combines technical impact with extortion. Encryption confirms the impact phase, but business risk already starts at data theft and credential compromise.

    Known IOCs and artefacts

    Hancitor-related activity is an important advisory artefact: loader behaviour, follow-on payloads, RAT communication and sudden process chains after phishing or download events.

    RDP use is a concrete access category. Monitor external RDP, RDP between servers, login from unknown infrastructure and RDP use by accounts that do not normally administer servers.

    Use CISA/FBI IOCs from AA22-335A for retro-hunting, but base structural detection on vulnerability exploitation, credential abuse, loader behaviour, data staging and lateral movement.

    Victim pattern and lessons

    Cuba affected multiple critical infrastructure sectors. That broad pattern points to opportunistic access and economic pressure rather than one narrow target group.

    The lesson is that known vulnerabilities and RDP are still enough for serious ransomware. Organisations often buy modern tooling while old internet-facing software or remote-access exceptions remain.

    For suppliers and MSPs, Cuba is especially relevant when they maintain management connections into customer environments.

    How to defend against Cuba

    Patch internet-facing software by risk, not by calendar. Vulnerabilities used by ransomware groups must be accelerated.

    Restrict RDP and external remote access to necessary paths with MFA, allowlists and central logging. Disable direct internet RDP.

    Detect loaders and follow-on payloads. A Hancitor-like event should trigger credential reset, host isolation and hunting for lateral movement.

    Monitor data staging, compression and outbound traffic. Cuba defence is not only preventing encryption, but also preventing data being used as leverage.

    Practical detection logic for Cuba

    Cuba detection starts with the initial-access routes from the CISA/FBI advisory: known vulnerabilities, phishing, compromised credentials and RDP. Put internet-facing applications, VPN and RDP into one risk picture.

    Hancitor is an important early signal. When a loader or RAT-like follow-on payload appears, the team must immediately search for stolen credentials, persistence, remote access and connections to external infrastructure.

    For internal movement, RDP, new services, admin logins and file-share reconnaissance are relevant. Link vulnerability events to identity events and server activity.

    Concrete hardening priorities

    Accelerate patching for commercial software reachable from the internet.

    Make RDP a managed protocol rather than a convenience feature: no direct internet RDP, MFA where remote access is needed, logging on source, target and account, and blocking between zones without an administration reason.

    Train incident response on loader-to-ransomware chains. Hancitor or RAT signals must trigger checks of passwords, tokens, scheduled tasks, services and remote access.

    Identity, naming and attribution

    For Cuba, the operational starting point is an exact identity match. The local dossier records the following names or aliases: Cuba ransomware, Cuba ransomware actors. An alias is a search aid, not independent evidence of shared operators. Similar names, reused logos and the same extortion vocabulary cannot establish a relationship between groups. Analysts should retain the original spelling of a claim and distinguish the publisher, malware family and suspected intrusion operator. Those roles can belong to different people. This prevents an incident being assigned to the wrong group simply because a filename or public post resembles an earlier case. Any proposed relationship needs its own dated, attributable source.

    Timeline and interpretation of dates

    The source registry date available for Cuba is 2021-02-03; the metadata snapshot was collected on 2026-09-15. These timestamps describe the available record, not a proven beginning of criminal operations. Registration may follow earlier activity, and a claim can concern an older incident. A defensible timeline separates suspected intrusion, data access, discovery by the victim, publication by the claimant and discovery by the monitoring service. The profile review date is another independent timestamp. Analysts should not silently convert one date into another. When sources disagree, preserve both observations and their provenance, then explain the uncertainty rather than presenting a falsely precise attack chronology.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    accessknown vulnerabilities in commercial softwareCISA AA22-335AObserved initial access technique.
    accessphishing campaignsCISA AA22-335AObserved initial access technique.
    accesscompromised credentialsCISA AA22-335AObserved initial access technique.
    toolingHancitor loaderCISA AA22-335AUsed to drop or execute stealers, RATs and ransomware.
    toolinglegitimate RDP toolsCISA AA22-335AUsed for remote access and movement.

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.