Description Summary
Cuba ransomware (also known as COLDDRAW) has been active since late 2019 and operates a Tor leak site themed with imagery of Cuba. Despite the name, it has no known ties to Cuba — operators are believed to be Russian-speaking. Cuba has been linked to the RomCom backdoor and Industrial Spy data-leak market.
Threat Actor
Russian-speaking actor with overlap with the RomCom RAT operators. FBI assessed total ransom payments exceeding USD 60 million.
Technical Indicators
Encryption Extension
.cuba
Encryption Algorithm
ChaCha20 + RSA-4096
Ransom Note Name
!!FAQ for Decryption!!.txt
Targeted Industries
Financial, Government, Healthcare, IT, Critical manufacturing
First Seen
December 2019
Last Seen
Active but reduced in 2025
Geographical Location
United States, Australia, Europe, Latin America
MITRE ATT&CK Matrix
| Tactic | TTP | Technique Name |
|---|---|---|
| Initial Access x 3 | T1566 | Phishing |
| T1190 | Exploit Public-Facing Application | |
| T1078 | Valid Accounts | |
| Execution x 1 | T1059 | Command and Scripting Interpreter |
| Execution Persistence x 1 | T1053 | Scheduled Task/Job |
| Defense Evasion x 2 | T1562.001 | Disable or Modify Tools |
| T1070.004 | File Deletion | |
| Discovery x 2 | T1083 | File and Directory Discovery |
| T1082 | System Information Discovery | |
| Lateral Movement x 2 | T1021.001 | Remote Services: RDP |
| T1021.002 | SMB/Windows Admin Shares | |
| Exfiltration x 2 | T1041 | Exfiltration Over C2 Channel |
| T1567.002 | Exfiltration to Cloud Storage | |
| Impact x 3 | T1486 | Data Encrypted for Impact |
| T1490 | Inhibit System Recovery | |
| T1489 | Service Stop |