Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Colddraw

Description

The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted.<br> <br> Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site.<br> <br> According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in 2023, there were indications that the developer behind the Cuba ransomware speaks Russian.<br> <br> The ransomware operators use a double extortion approach, and following the USA, in August 2022, it was believed that the Cuba ransomware group had compromised 101 entities, demanding $145 million in ransom payments and receiving up to $60 million.<br> <br> The group used a similar set of TTPs, with only a slight change each year, as they generally consist of LOLBins (executables that are part of the operating system and can be exploited to support an attack), exploits, off-the-shelf and custom malware, as well as intrusion tools like Cobalt Strike and Metasploit.<br> <br> In 2022, the group allegedly developed a relationship with operators of the Industrial Spy market, using their platform as a means of data leakage.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs Known victims: 103 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

The Cuba Ransomware group, also known as Colddraw, is a sophisticated cybercriminal organization specializing in ransomware attacks. They use double extortion tactics to maximize payouts and have targeted numerous victims across various industries, resulting in significant financial losses.

Goals & Targeting

Cuba Ransomware's primary goals are financial gain through ransoms and secondary gains from data exfiltration for sale or public release. The group likely targets sectors with significant financial value or sensitive information, such as healthcare, education, energy, and manufacturing. Their broad targeting strategy reflects a focus on maximizing revenue rather than sector-specific interests.

Enhanced Description

Cuba Ransomware emerged in 2019 and operates under the alias Colddraw. Despite its Cuban-inspired name, there is no confirmed link to Cuba; instead, evidence suggests a Russian-speaking developer. Known for embedding the string 'Fidel' at the beginning of encrypted files as a marker, they employ a double extortion approach: encrypting data and threatening data leaks if ransom isn't paid. Notable TTPs include the use of Cobalt Strike and Metasploit alongside custom tools. They target high-value assets across industries, with over 103 known victims to date.

Key Capabilities

  • Double extortion ransomware
  • Use of Cobalt Strike for initial access
  • Encryption leveraging LOLBins and process injection techniques
  • Data exfiltration via established marketplaces
  • Russian-language communication among operators

MITRE ATT&CK Tactics

Initial Access (TA0001)
Execution (TA0002)
Lateral Movement (TA0003)

ATT&CK Techniques

T1059.003 - Cobalt Strike usage
T1055 - Process Injection for privilege escalation
T1566.001 - Data Exfiltration via network share

Software / Tooling

Cobalt Strike
Metasploit
Colddraw Ransomware

Campaigns & Victims

The group has demonstrated a steady operational tempo since 2019, with campaigns peaking in mid-2022 where 101 entities were targeted. Their victims include businesses and organizations from various industries globally, leveraging double extortion to coerce higher ransom payments ($60M-$145M). Notable for adapting their techniques minimally yet effectively each year.

IOC Patterns

  • Spear-phishing emails with malicious attachments or links
  • Use of Cobalt Strike for compromising systems
  • Encrypted files marked with '.Fidel' suffix
  • Ransom notes demanding cryptocurrency payments

Recommended Actions

  • Implement endpoint detection to monitor Cobalt Strike TTPs.
  • Prevent macro-based attacks in Office documents.
  • Secure RDP access and eliminate excessive administrative privileges.
  • Establish offline backups regularly tested for integrity.
  • Deploy multi-factor authentication for critical accounts.
  • Educate users on phishing signs.

Suggested Tags

ransomware
double extortion
financial-gain

Confidence Assessment

High confidence in identifying Cuba Ransomware as a distinct threat group, with clear TTPs and financial incentives. Remaining uncertainties include precise targeting patterns across industries due to limited data.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

2

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
double extortion
financial-gain

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Feb 3, 2021
Last Seen
Feb 1, 2024
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.