Skip to content
CTI Academy Sponsor CTI Academy
Ransomware group

Cuba ransomware

2 victims listed on the Cuba leak site across 2 countries. Most recent disclosure .

Victims
2
0% of all tracked
Countries
2
Most: France
Sectors
2
Most: Healthcare
First seen
Jan 2024
In this database

ThreatAI analysis

Compiled from the ransomware.live profile for Cuba and from this database. Figures and technique mappings are quoted from the source data, not inferred.

Who Cuba is

The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted. Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site. According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in

Recorded activity

Disclosures attributed to Cuba in this database run from January 2024 to February 2024, totalling 2 victims — 0% of everything tracked here. Cuba has listed victims in 2 countries in this database, most often France, followed by Belgium. The sectors appearing most in its listings are Healthcare, Manufacturing.

How Cuba is documented to operate

External Remote Services T1133 Persistence Initial Access

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network.

Mitigations: Limit Access to Resource Over Network, Restrict Web-Based Content, Network Segmentation, Multi-factor Authentication, Disable or Remove Feature or Program

MITRE ATT&CK reference
Native API T1106 Execution

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors.

Mitigations: Execution Prevention, Behavior Prevention on Endpoint

MITRE ATT&CK reference
Exploitation for Privilege Escalation T1068 Privilege Escalation

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.

Mitigations: Execution Prevention, Threat Intelligence Program, Application Isolation and Sandboxing, Exploit Protection, Update Software

MITRE ATT&CK reference

MITRE ATT&CK techniques attributed to Cuba across its recorded activity. They describe the group overall, not any single incident.

Tooling observed in Cuba operations

  • Mimikatz
  • Avast Anti-Rootkit driver
  • PsExec
  • Termite
  • Cobalt Strike
  • Meterpreter
  • NetSupport

Software reported in use by Cuba. Most are legitimate administration or transfer utilities; their presence in an environment is a signal to investigate, not proof of compromise.

Indicators of compromise

Showing a sample of 3 EMAIL on file. Hashes and network indicators published for Cuba. Leak-site addresses are deliberately excluded. Indicators age quickly — treat a match as a starting point for investigation, and an absence of matches as no assurance.

YARA detection rules

cuba.yar
/*
Cuba ransomware
*/

rule Cuba_Ransomnote
{
    meta:
        author = "ransomware.live"
        family = "ransomware.cuba"
        description = "Detects Cuba ransomware ransom note"
        date = "2026-05-04"
        severity = 7
        score = 70

    strings:
        $s1 = ".cuba" ascii nocase
        $s2 = "HOW-TO-DECRYPT.txt" ascii nocase
        $s3 = "cuba.barzini" ascii nocase
        $s4 = "cubahitaramos" ascii nocase

    condition:
        any of them
}

rule Cuba_PE
{
    meta:
        author = "ransomware.live"
        family = "ransomware.cuba"
        description = "Detects Cuba ransomware executable"
        date = "2026-05-04"
        severity = 9
        score = 90

    strings:
        $s1 = "\x00Cuba-Locker\x00" ascii
        $s2 = "\x00CUBA\x00" ascii wide
        $s3 = "HOW-TO-DECRYPT.txt" ascii

    condition:
        uint16(0) == 0x5A4D and 2 of them
}

Community-contributed rules for Cuba, reproduced as published. Test them against your own corpus before relying on them: rule quality and false-positive behaviour vary by author.

Threat actor analysis

Cuba has disclosed 2 victims on its leak site, 0% of all ransomware listings tracked in this database. Its earliest disclosure here dates to January 2024.

The group has listed organisations in 2 countries, most often in France (1 victims), followed by Belgium.

By industry, its listings concentrate in Healthcare, Manufacturing — sectors that hold sensitive data or cannot tolerate long outages, both of which raise the pressure to pay.

Like most current ransomware operations, Cuba is likely to use double extortion: data is stolen before files are encrypted, and organisations that refuse to pay are named on the leak site with the stolen data as leverage.

Cuba victims 2

Organization Disclosed
dms-imaging
FRFrance
deknudtframes.be
BEBelgium

Frequently asked questions

What is Cuba ransomware?

Cuba is a ransomware threat group that has claimed 2 victims since its first known activity in January 2024. The group operates by infiltrating target networks, exfiltrating data, encrypting files, and threatening to publish stolen data on a dark web leak site if the ransom is not paid.

How many victims has Cuba attacked?

Cuba has claimed 2 victims in our database, representing 0% of all tracked ransomware attacks. The most targeted countries are France, Belgium.

Which countries does Cuba target?

Cuba has attacked organizations in 2 countries. The top targeted countries are: France, Belgium.

Which industries does Cuba target?

Cuba most frequently targets the Healthcare, Manufacturing sectors based on victim disclosures in our database.

Is Cuba still active?

Cuba's most recent victim disclosure in our database was on February 1, 2024. Ransomware groups frequently rebrand or go dormant; monitor this page and our ransomware map for the latest activity.