Malware.View on attack.mitre.org
Cuba is a Windows-based ransomware family that has been used against financial institutions, technology, and logistics organizations in North and South America as well as Europe since at least December 2019.
| Technique | Procedure example |
|---|---|
| T1007 System Service Discovery |
Cuba can query service status using |
| T1016 System Network Configuration Discovery |
Cuba can retrieve the ARP cache from the local system by using |
| T1027 Obfuscated Files or Information |
Cuba has used multiple layers of obfuscation to avoid analysis, including its Base64 encoded payload. |
| T1027.002 Software Packing |
Cuba has a packed payload when delivered. |
| T1036.005 Match Legitimate Resource Name or Location |
Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs. |
| T1049 System Network Connections Discovery |
Cuba can use the function |
| T1056.001 Keylogging |
Cuba logs keystrokes via polling by using |
| T1057 Process Discovery |
Cuba can enumerate processes running on a victim's machine. |
| T1059.001 PowerShell |
Cuba has been dropped onto systems and used for lateral movement via obfuscated PowerShell scripts. |
| T1059.003 Windows Command Shell |
Cuba has used |
| T1070.004 File Deletion |
Cuba can use the command |
| T1083 File and Directory Discovery |
Cuba can enumerate files by using a variety of functions. |
| T1105 Ingress Tool Transfer |
Cuba can download files from its C2 server. |
| T1106 Native API |
Cuba has used several built-in API functions for discovery like GetIpNetTable and NetShareEnum. |
| T1134 Access Token Manipulation |
Cuba has used |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.