Cuba ransomware exploits vulnerabilities in Microsoft Exchange to gain access to corporate networks and encrypt devices.

See also: Ransomware attacks: The nightmare doesn't stop after the ransom is paid
Cybersecurity firm Mandiant is tracking a ransomware gang known as UNC2596 and the ransomware itself, known as COLDDRAW. However, the ransomware is better known by the name Cuba.
This is a ransomware operation that began in late 2019 and while initially slow-moving, its activity skyrocketed in 2020 and 2021. This increase in activity led the FBI to issue an advisory about Cuba ransomware in December 2021, warning that the gang behind it had breached 49 critical infrastructure organizations in the U.S
According to Mandiant, Cuba ransomware primarily targets the United States and Canada.
The ransomware gang behind the Cuba ransomware has been exploiting Microsoft Exchange vulnerabilities to deploy web shells, RATs, and backdoors to establish its foothold in the target network since August 2021.
These backdoors include Cobalt Strike or the remote access tool NetSupport Manager, but the group also uses its own tools "Bughatch", "Wedgecut", and "eck.exe" and Burntcigar.
See also: Entropy ransomware linked to Dridex malware downloader
Wedgecut comes in the form of an executable named “check.exe”, which is an identification tool that enumerates the Active Directory directory service via PowerShell.

Bughatch is a downloader that retrieves PowerShell scripts and files from the C&C server. To avoid detection, it loads into memory from a remote URL.
Burntcigar is a utility that can terminate processes at the kernel level, exploiting a flaw in an Avast program, which is included in the “bring your own vulnerable driver” attack tool.
Malicious users escalate their privileges on the network, using stolen account credentials derived from readily available tools Mimikatz and Wicker.
They then perform network reconnaissance with Wedgecut and move laterally with RDP, SMB, PsExec , and Cobalt Strike.
The subsequent development is Bughatch loaded by Termite, followed by Burntcigar, which sets the stage for data extraction and file encryption by disabling security tools.
See also: LockBit & Conti: The most active ransomware in the industrial sector
The Cuba operation will likely turn its attention to other vulnerabilities when there are no more valuable targets running unpatched Microsoft Exchange servers.
This means that applying available security updates as soon as software vendors release them is key to maintaining a strong security posture against even the most sophisticated hackers.
