The Cuba Ransomware gang collaborated with the operators of the Hancitor malware to gain easier access to compromised corporate networks.

See also: QNAP warns of AgeLocker ransomware attacks on NAS devices
The Hancitor downloader (Chancitor) has been around since 2016, when Zscaler detected it distributing the Vawtrak credential-stealing Trojan. Since then, many campaigns have been detected over the years where Hancitor installs password-stealers, such as Pony, Ficker, and most recently, Cobalt Strike.
Hancitor is usually distributed through malicious spam campaigns that pretend to be DocuSign invoices, as you can see below.

When a recipient clicks the “Sign document” link, it will download a malicious Word document that attempts to convince the target to disable protections.
Once the protections are disabled, malicious macros will be activated to download and install the Hancitor downloader.
See also: The Babuk ransomware gang stops its "operation"!
Just as Ryuk and Conti teamed up with TrickBot and Egregor and ProLock teamed up with QBot, so too does Cuba Ransomware team up with Hancitor to gain access to compromised networks.
Collaboration can accelerate attacks
Since its release in late 2019, the Cuba Ransomware has not been particularly active compared to other ransomware operations, such as REvil, Avaddon, Conti, and DoppelPaymer.
His most well-known attack was against ATFS, a widely used payment processor for local and state governments.
Since its attacks are now fueled by spam campaigns, we expect to see an increase in victims, and soon.
See also: Brazil: REvil ransomware targeted Rio Grande do Sul's judicial system
It should also be noted that while the Cuba Ransomware uses a photo of Fidel Castro and is named after the country of Cuba, its operators are based in Russia, according to cybersecurity firm Profero. This is a conclusion Profero came to after spotting the Russian language on the gang's data leak website.
Information source: bleepingcomputer.com
