Cuba Ransomware

Description Summary

Cuba ransomware (also known as COLDDRAW) has been active since late 2019 and operates a Tor leak site themed with imagery of Cuba. Despite the name, it has no known ties to Cuba — operators are believed to be Russian-speaking. Cuba has been linked to the RomCom backdoor and Industrial Spy data-leak market.

Threat Actor

Russian-speaking actor with overlap with the RomCom RAT operators. FBI assessed total ransom payments exceeding USD 60 million.

Technical Indicators

Encryption Extension
.cuba
Encryption Algorithm
ChaCha20 + RSA-4096
Ransom Note Name
!!FAQ for Decryption!!.txt
Targeted Industries
Financial, Government, Healthcare, IT, Critical manufacturing
First Seen
December 2019
Last Seen
Active but reduced in 2025
Geographical Location
United States, Australia, Europe, Latin America

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop