Skip to content
CTI Academy Sponsor CTI Academy
Ransomware victim Healthcare

dms-imaging

Listed by Cuba on · organisation based in France

dms.com

Disclosed
Feb 1, 2024
Leak-site listing date
Threat group
Cuba
2 victims listed
Country
France
#6 most targeted
Sector
Healthcare

ThreatAI analysis

Compiled from this incident record and the threat intelligence profile for Cuba. Figures and technique mappings are quoted from the source data, not inferred.

About the Cuba group

The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted. Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site. According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in Cuba has listed 103 victims since February 2021.

How Cuba is documented to operate

External Remote Services T1133 Persistence Initial Access

Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally. Access to Valid Accounts to use the service is often a requirement, which could be obtained through credential pharming or by obtaining the credentials from users after compromising the enterprise network.

Mitigations: Limit Access to Resource Over Network, Restrict Web-Based Content, Network Segmentation, Multi-factor Authentication, Disable or Remove Feature or Program

MITRE ATT&CK reference
Native API T1106 Execution

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors.

Mitigations: Execution Prevention, Behavior Prevention on Endpoint

MITRE ATT&CK reference

MITRE ATT&CK techniques attributed to Cuba across its recorded activity, not a finding about how dms-imaging was reached.

Incident analysis

dms-imaging was listed by Cuba ransomware, a group with 2 victims recorded in this database. The listing appeared on the group's leak site on February 1, 2024.

dms-imaging is based in France and operates in the Healthcare sector. France ranks #6 worldwide for ransomware disclosures, with 563 victims in this database.

Sector context. Healthcare organisations are high-value ransomware targets because patient data is extremely sensitive, regulatory penalties for breaches are severe, and operational downtime can threaten patient safety — all factors that increase ransom payment pressure.

Cuba typically follows a double extortion model: data is exfiltrated from the victim's systems before files are encrypted, so the victim faces two demands at once — pay to restore access, and pay to keep stolen data unpublished. The leak site, where this listing appeared, is the lever for the second demand.

Frequently asked questions

Was dms-imaging attacked by ransomware?

Yes. dms-imaging was listed as a victim of the Cuba ransomware group on February 1, 2024. The organisation is based in France and operates in the Healthcare sector. The disclosure appeared on the group's dark web leak site.

Which ransomware group attacked dms-imaging?

dms-imaging was attacked by Cuba ransomware. Cuba is one of the most active ransomware groups, having claimed 2 victims globally. The group typically employs a double-extortion model: encrypting the victim's files and threatening to publish stolen data.

When did the dms-imaging ransomware attack occur?

The ransomware attack on dms-imaging was disclosed on February 1, 2024. This date reflects when the victim was published on the threat group's leak site, which may differ from the actual date of initial compromise.

What data was stolen in the dms-imaging ransomware attack?

The specific data stolen from dms-imaging has not been independently verified by this platform. Ransomware groups typically exfiltrate data before encrypting systems and use the threat of publication to pressure victims. As a Healthcare organisation, dms-imaging likely held patient records, medical data, and personally identifiable information (PII).

How can organisations protect against Cuba attacks?

To defend against Cuba and similar threat actors, organisations should: maintain regular offline backups tested for restoration; implement network segmentation to limit lateral movement; deploy multi-factor authentication on all remote access; use endpoint detection and response (EDR) tools; conduct regular phishing and security awareness training; and monitor threat intelligence feeds for indicators of compromise (IOCs) associated with active groups.