Cuba

S0625

Malware.View on attack.mitre.org

About this malware

Cuba is a Windows-based ransomware family that has been used against financial institutions, technology, and logistics organizations in North and South America as well as Europe since at least December 2019.

Techniques used23

Procedure examples23

TechniqueProcedure example
T1007
System Service Discovery

Cuba can query service status using QueryServiceStatusEx function.

T1016
System Network Configuration Discovery

Cuba can retrieve the ARP cache from the local system by using GetIpNetTable.

T1027
Obfuscated Files or Information

Cuba has used multiple layers of obfuscation to avoid analysis, including its Base64 encoded payload.

T1027.002
Software Packing

Cuba has a packed payload when delivered.

T1036.005
Match Legitimate Resource Name or Location

Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs.

T1049
System Network Connections Discovery

Cuba can use the function GetIpNetTable to recover the last connections to the victim's machine.

T1056.001
Keylogging

Cuba logs keystrokes via polling by using GetKeyState and VkKeyScan functions.

T1057
Process Discovery

Cuba can enumerate processes running on a victim's machine.

T1059.001
PowerShell

Cuba has been dropped onto systems and used for lateral movement via obfuscated PowerShell scripts.

T1059.003
Windows Command Shell

Cuba has used cmd.exe /c and batch files for execution.

T1070.004
File Deletion

Cuba can use the command cmd.exe /c del to delete its artifacts from the system.

T1083
File and Directory Discovery

Cuba can enumerate files by using a variety of functions.

T1105
Ingress Tool Transfer

Cuba can download files from its C2 server.

T1106
Native API

Cuba has used several built-in API functions for discovery like GetIpNetTable and NetShareEnum.

T1134
Access Token Manipulation

Cuba has used SeDebugPrivilege and AdjustTokenPrivileges to elevate privileges.

View all 23 procedure examples

Groups that use it0

None recorded.

Campaigns0

None recorded.

References1

  1. McAfee Cuba April 2021 Open source
    Roccio, T., et al. (2021, April). Technical Analysis of Cuba Ransomware. Retrieved June 18, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.