Site icon TheCyberThrone

Cuba Ransomware Latest Tactics Analysis

Advertisements

Researchers have unveiled research into the activities of the notorious Cuba ransomware group known as Cuba targeting organizations worldwide, spanning various industries.

The group has changed names several times since its inception. The following aliases it has used:

Back in December 2022, researchers detected a suspicious incident on a client’s system. This initial discovery unearthed three mysterious files that led to the activation of the komar65 library, also referred to as BUGHATCH.

Advertisements

BUGHATCH, a sophisticated backdoor that operates in process memory, connecting to a C2 server to receive instructions. This malware can download software like Cobalt Strike Beacon and Metasploit, and its use of vulnerabilities in the Veeam backup software strongly suggests Cuba’s involvement.

The investigation also revealed the presence of Russian-speaking members within the group, indicated by references to the “komar” folder, which translates to “mosquito” in Russian. The group has further enhanced the malware’s capabilities with additional modules, including one responsible for collecting and sending system information to a server via HTTP POST requests.

Another malware attributed to Cuba known as BURNTCIGAR malware, incorporating encrypted data to avoid antivirus detection also identified.

Cuba, a single-file ransomware strain, operates without additional libraries, making it challenging to detect. Despite their prolonged presence in the cybersecurity spotlight, Cuba remains dynamic and constantly refines its techniques, including data encryption and tailored attacks to extract sensitive information.

Four extortion models exist today in terms of tools used for pressuring the victim.

Advertisements
Source : Kaspersky

Researchers emphasized the importance of staying informed and proactive against evolving cyber-threats and encouraged organizations to follow best practices to safeguard against ransomware.

This research was conducted and documented by researchers from Kaspersky

Indicators of Compromise

Exit mobile version