---
title: The Ransomware Gang That You Should Be Watching Out For
description: Late last year, the FBI issued a warning about the Cuba ransomware group. You may not have heard of them, but that doesn’t mean they shouldn’t be on your radar. In their warning, the FBI claimed that as of November 2021, “49 entities in five critical infrastructure sectors” had been compromised by the COLDDRAW ransomware used by the Cuba group, and they’re showing no signs of stopping.
image: https://csacyber.com/hubfs/ransomware-gang1.png
---

[Skip to content](https://csacyber.com/blog/the-ransomware-gang-that-you-should-be-watching-out-for#main-content)

[![CSA Cyber - Cyber Security Solutions to Protect your People](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=300&height=108&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber - Cyber Security Solutions to Protect your People")](https://csacyber.com/)

- Services 
    - [Offensive Security Services](https://csacyber.com/offensive-security-services) 
          - [Penetration Testing](https://csacyber.com/penetration-testing)
          - [Red Teaming and attack simulations](https://csacyber.com/offensive-security-services#red-teaming)
          - [Continuous testing](https://csacyber.com/offensive-security-services#continuous-assurance)
          - [Managed offensive security](https://csacyber.com/offensive-security-services#managed-offensive)
    - [Consultancy Services](https://csacyber.com/cyber-consultancy-services) 
          - [Frameworks & assessments](https://csacyber.com/cyber-consultancy-services/frameworks-and-assessments)
          - [Data protection](https://csacyber.com/cyber-consultancy-services#data-protection)
          - [Virtual leadership](https://csacyber.com/cyber-consultancy-services#virtual-leadership)
          - [Technical security consulting](https://csacyber.com/cyber-consultancy-services#technical-consultancy)
          - [Governance, Risk & Compliance (GRC)](https://csacyber.com/cyber-consultancy-services/governance-risk-and-compliance-services)
    - [Extended Managed Security Services](https://csacyber.com/extended-managed-security-services) 
          - [Microsoft Sentinel SIEM](https://csacyber.com/extended-managed-security-services#microsoft-sentinel)
          - [SOC services](https://csacyber.com/extended-managed-security-services#soc-services)
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/extended-managed-security-services#cyber-helpdesk)
    - [Incident Response Services](https://csacyber.com/incident-response-services) 
          - [Emergency Incident Response](https://csacyber.com/urgent/emergency-incident-response)
          - [Incident Response Retainer](https://csacyber.com/incident-response-services)
          - [Cyber Incident Readiness & Response Planning](https://csacyber.com/incident-response-services)
          - [Tabletop Exercises & Live-Range Engagements](https://csacyber.com/incident-response-services)
    - [Specialist Security Services](https://csacyber.com/specialist-services) 
          - [AI Security](https://csacyber.com/cyber-services-for-ai)
          - [Operational Technology (OT)](https://csacyber.com/specialist-services#operational-technology)
          - [Cyber security for Private Equity](https://csacyber.com/specialist-services#mergers-and-acquisitions)
          - [Cyber training and education](https://csacyber.com/specialist-services#training-and-education)
          - [Virtual leadership](https://csacyber.com/specialist-services#leadership)
    - [Cyber Technologies](https://csacyber.com/cyber-technologies) 
          - [SentinelOne Endpoint Detection & Response (EDR)](https://csacyber.com/cyber-technologies#sentinelone)
          - [AppGuard Endpoint & Server Zero Trust Protection](https://csacyber.com/cyber-technologies#appguard)
          - [Qualys Vulnerability Management as a Service (VMaaS)](https://csacyber.com/cyber-technologies#qualys-vmaas)
          - [Lookout Mobile Device Protection](https://csacyber.com/cyber-technologies#lookout)
          - [ThreatER DNS Protection](https://csacyber.com/cyber-technologies#threater-dns)
          - [Cyber Security Awareness & Training platform](https://csacyber.com/cyber-technologies#boxphish)
- [About](https://csacyber.com/about-us) 
    - [Careers](https://csacyber.com/careers)
    - [Certifications](https://csacyber.com/certifications-and-awards)
- [Blog](https://csacyber.com/blog)
- [Support Centre](https://csacyber.com/support)
- Resources 
    - [Case Studies](https://csacyber.com/case-studies)
    - [Downloads & Reports](https://csacyber.com/downloads-and-reports)
    - [Webinars](https://csacyber.com/webinars)
    - [Partners](https://csacyber.com/partners)
    - [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)
- [Contact](https://csacyber.com/contact-us)

- Search Search
  
  Search

 March 15, 2022

 3 min read time

# The Ransomware Gang That You Should Be Watching Out For

![Cyber Security Associates](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e) [Written by: Cyber Security Associates -](https://csacyber.com/blog/author/cyber-security-associates)

[Article](https://csacyber.com/blog/tag/article) 

![](https://csacyber.com/hubfs/ransomware-gang1.png)

### Executive Summary

Late last year, the FBI issued a warning about the Cuba ransomware group. You may not have heard of them, but that doesn’t mean they shouldn’t be on your radar. In their warning, the FBI claimed that as of November 2021, “49 entities in five critical infrastructure sectors” had been compromised by the COLDDRAW ransomware used by the Cuba group, and they’re showing no signs of stopping. Another infamous group, HAFNIUM, made a name for themselves by targeting zero-day exploits, and it looks like Cuba are following in their footsteps.

### What is the Cuba ransomware group?

Back in March 2021, companies around the world were left vulnerable after the state-sponsored HAFNIUM group identified vulnerabilities in Microsoft’s Exchange software, known as zero-days. The vulnerabilities, identified as ProxyLogon and ProxyShell, were exploited by HAFNIUM to deploy their ransomware. Now, in 2022, the Cuba ransomware group has been found to be exploiting these same vulnerabilities, as well as using other methods to access systems.

The ransomware group is also known as UNC2596, as well as COLDDRAW, which is the name of the ransomware they primarily use. The group has been spotted using a range of reconnaissance tools, as well as exchange vulnerabilities and known malware, to infect systems with their COLDDRAW ransomware and potentially carry out other malicious activity.

It’s been reported that the Cuba Ransomware group, after successfully compromising a system, deploys the COLDDRAW ransomware, and encrypts system files with the ‘.cuba’ extension, which they then demand ransom for the decryption. If the victim chooses not to pay the ransom, or just does not pay it in time, their data may be leaked and posted on the group’s shaming site (as shown in the image below).

![](https://csa.limited/assets/img/blog/cuba-ransomware-site.png)

### How does the Cuba ransomware group gain entry?

The group has been observed using a range of bespoke tools for reconnaissance, including the following:

WEDGECUT - this reconnaissance tool arrives in the form of an executable labelled ‘check.exe,’ and is used to identify if a list of hosts or IP addresses are online

BURNTCIGAR – this is an endpoint security software termination tool, and can terminate processes by exploiting a flaw in the Avast driver.

BUGHATCH – this downloader receives commands and code from a C2 (command-and-control) server for execution on a compromised system.

There are multiple ways the group can gain access to systems. Other than using breached credentials and exploiting Microsoft Exchange vulnerabilities, they’ve also used the Hancitor malware (also known as Chanitor). This is an infamous malware loader, which, after connecting to a C2 server, downloads other malicious software such as COLDDRAW.

When it comes to the Microsoft Exchange vulnerabilities, the Cuba group is believed to be exploiting a particular set of flaws, which the Microsoft Security Response Center (MSRC) has identified under the Common Vulnerabilities and Exposures (CVE) system. Cuba will first attack CVE-2021-26855 to authenticate themselves, and then use CVE-2021-26857 to escalate their privileges to system access (essentially giving themselves full machine control). Finally, they could use the methods found under CVE-2021-26858 and CVE-2021-27065 to write and exfiltrate the sensitive data or, potentially, load COLDDRAW. All of these vulnerabilities should be looked at and patched or updated, if that hasn’t been done already.

### Why should you care?

So far, the main documented targets have just been US entities, including organisations in the healthcare, manufacturing, IT, and finance sectors. According to the FBI, the Cuba group has extorted $43.9 million (or £33.4 million) from their victims so far. However, the risks of being attacked by this kind of ransomware group, and having your sensitive data laid bare, aren’t just financial. As well as paying a high ransom, your organisation and your brand will also suffer reputational damage, and potential clients will think twice about dealing with you in the future after a leak. You may also have to pay GDPR fines, and end up losing out on even more money. Even if you’re not in the US, you should still be looking to boost your cyber defences and patch any vulnerabilities, to protect your organisation from Cuba or any similar ransomware groups that might be out there. Gangs like these are always on the lookout for different ways to turn a profit, and exploiting unpatched vulnerabilities and successful social engineering is all in a day’s work for malicious actors.

### How can you protect yourself?

We believe that cyber security should be available to everyone, which is why we recently published some emergency cyber hygiene advice on our blog. The post contains some very useful and crucial advice for anyone looking to bolster their cyber defences at the moment, and is worth a read. Cyber Security Associates also offers a wide range of bespoke training material, ranging from affordable enterprise e-learning courses to phishing campaign exercises, allowing you and your organisation to be prepared, and ensure provisions are met to guarantee that your data is as safe as it possibly can be. To find out more, don’t hesitate to get in touch with us.

Related Posts

## You may also like this

[Similar Articles](https://csacyber.com/blog)

[![](https://csacyber.com/hs-fs/hubfs/20230510-N1005919-Edit1.jpg?width=624&height=427&name=20230510-N1005919-Edit1.jpg)](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 August 24, 2026

 2 min read

### [FluidOne Group appoints Charly Davis as Managing Director of CSA Cyber to advance its security-first strategy](https://csacyber.com/blog/fluidone-group-appoints-charly-davis-as-managing-director-of-csa-cyber-to-advance-its-security-first-strategy)

 Experienced industry leader joins FluidOne to strengthen integrated cyber, IT and secure networking...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Untitled%20design.jpg?width=624&height=427&name=Untitled%20design.jpg)](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 August 20, 2026

 2 min read

### [CSA Cyber and FluidOne named as suppliers on G-Cloud 15](https://csacyber.com/blog/csa-cyber-and-fluidone-named-as-suppliers-on-g-cloud-15)

 CSA Cyber (CSA), part of the FluidOne Group, has been named as a supplier on Government Commercial...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![](https://csacyber.com/hs-fs/hubfs/Engineered%20to%20Endure%20Campaign%20Assets%20(2).png?width=624&height=427&name=Engineered%20to%20Endure%20Campaign%20Assets%20(2).png)](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 August 20, 2026

 6 min read

### [Why organisations lose security visibility without realising it](https://csacyber.com/blog/why-organisations-lose-security-visibility-without-realising-it)

 Before an organisation can understand risk, maintain control or respond effectively to emerging...

[![CSA Cyber](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Stacked.png?width=40&height=40&name=CSA%20Cyber%20Logo%20FNL_Stacked.png) CSA Cyber](https://csacyber.com/blog/author/csa-cyber)

[![CSA Cyber Logo FNL_Full Logo](https://csacyber.com/hs-fs/hubfs/CSA%20Cyber%20Logo%20FNL_Full%20Logo.png?width=3463&height=1248&name=CSA%20Cyber%20Logo%20FNL_Full%20Logo.png "CSA Cyber Logo FNL_Full Logo")](https://csacyber.com/)

Established in 2013, Cyber Security Associates Limited trading as CSA Cyber provides cyber consultancy and cyber managed services which help to detect, protect and educate against the ever-changing cyber threat. We have built our team from a foundation of Government (ex-Military) and Commercially experienced specialists all holding current and relevant cyber certifications. Today our core services are based around a 24/7 Security Operations Centre (SOC) based in Gloucester.

#### News & Resources

- [Blog](https://csacyber.com/blog)
- [Case Studies](https://csacyber.com/case-studies)
- [Downloads & Reports](https://csacyber.com/downloads-and-reports)
- [Webinars](https://csacyber.com/webinars)
- [Careers](https://csacyber.com/careers)
- [Cyber Bundles (IT MSPs)](https://csacyber.com/cyber-bundles)

#### Quick Links

- [About Us](https://csacyber.com/about-us)
- [Certifications](https://csacyber.com/certifications-and-awards)
- [Our Parent Company](https://www.fluidone.com)
- [Partners](https://csacyber.com/partners)
- [Contact Us](https://csacyber.com/contact-us)
- [Anti Bribery Policy](https://csacyber.com/hubfs/CSAAnti-BriberyPolicy.pdf)
- [Complaints Policy](https://csacyber.com/hubfs/CSAComplaintsPolicy.pdf)
- [Corporate Social Responsibility Policy](https://csacyber.com/hubfs/CSACorporateSocialResponsibilityPolicy.pdf)
- [Slavery and Human Trafficking Statement](https://csacyber.com/hubfs/CSASlaveryandHumanTraffickingStatement.pdf)
- [NCSC CHECK Status Verification](https://www.ncsc.gov.uk/organisation/csa-cyber/check-penetration-testing)
- [CREST Approved Certification Verification](https://www.crest-approved.org/member_companies/csa-cyber/)

#### Contact Information

**United Kingdom - London**

Cyber Security Associates Ltd

5 Hatfields, London, SE1 9PG

 

**United Kingdom - Gloucester**

Cyber Security Associates Ltd

Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ

 

**Phone:** [+44(0) 300 303 4691](tel:03003034691)

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

**United States of America**

Cyber Security Associates Inc.

6010 W. Spring Creek Pkwy, Plano, Texas, 75024

 

**Phone:** [+1 469 750 1695](tel:14697501695) 

**Email:** [hello@csacyber.com](mailto:hello@csacyber.com)

 

[![trust-pilot](https://csacyber.com/hs-fs/hubfs/trust-pilot.png?width=178&height=104&name=trust-pilot.png)](https://uk.trustpilot.com/review/csa.limited)

 

---

- [Website Terms of Use](https://csacyber.com/website-terms-of-use)
- [Website Privacy Policy](https://csacyber.com/privacy-notice)
- [Website Cookie Policy](https://csacyber.com/cookie-policy)

 Copyright 2026. Cyber Security Associates Ltd [Follow us on Facebook](https://www.facebook.com/CSALIMITED/) [Follow us on LinkedIn](https://www.linkedin.com/company/csa-cyber/) [Follow us on Twitter](https://twitter.com/cybersecurityis) [Follow us on Facebook](https://www.youtube.com/@cybersecurityassociateslim) [Follow us on Facebook](https://www.instagram.com/cybersecurityassociates)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Cyber Security Associates",
    "url" : "https://csacyber.com/blog/author/cyber-security-associates"
  },
  "dateModified" : "2024-12-06T15:17:05.331Z",
  "datePublished" : "2022-03-15T04:00:00.000Z",
  "headline" : "The Ransomware Gang That You Should Be Watching Out For",
  "image" : [ "https://csacyber.com/hubfs/ransomware-gang1.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://csacyber.com/blog/the-ransomware-gang-that-you-should-be-watching-out-for",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://csacyber.com/hubfs/csacyber-logo-black-01.svg"
    },
    "name" : "Cyber Security Associates Ltd"
  }
}
```