HomeSecurityCuba ransomware: New variant detected in recent attacks

Cuba ransomware: New variant detected in recent attacks

A new version of Cuba ransomware has been detected in recent attacks.

Cuba ransomware

Cuba ransomware was most active during 2021, when its operators collaborated with the gang behind the Hancitor malwareto gain initial access to victims’ systems. By the end of the year, the ransomware had compromised 49 critical infrastructure organizations in the United States.

See also: Emotet: Steals credit card information from Chrome users

However, the new year has seen ransomware become less active, with few new victims. However, Mandiant researchers have identified some signs that indicate that the group behind the Cuba ransomware is still active.

Also, now, Trend Micro analysts are reporting a surge in infections related to Cuba. The attacks began in March and continued strongly until April 2022.

Cuba ransomware: New variant detected in recent attacks

The hackers behind the Cuba ransomware had recorded three victims in April and one in May on their Tor site. However, the attacks that led to the release of these files likely took place earlier.

The number of victims is not large, but it is worth noting that compared to other ransomware, “Cuba” is generally more selective, only hitting large organizations.

See also: Black Basta ransomware: Linux version targets VMware ESXi servers

Cuba ransomware: New version detected

In late April, researchers at Trend Micro discovered a new version that included minor additions and changes, making the ransomware even more dangerous. More worryingly, however, this new version shows that the company is still alive and actively developing its encryptor.

The updates have not changed the core functionality of Cuba ransomware, but may have brought some improvements to its execution.

The malware now terminates more processes before encryption, including Outlook, MS Exchange, and MySQL. Ransomware encryptors terminate services to prevent these applications from locking files and preventing them from being encrypted.

Additionally, it appears that the exclusion list has been expanded with more directories and file types to be ignored during encryption. This prevents execution loops that can lead to corrupted files that cannot be restored. If the files are corrupted, victims will have no reason to pay for decryption.

See also: Ransomware attacks: Hackers secretly blackmail victims!

Finally, in the new version of Cuba ransomware, the gang has made some changes to the ransom notes, adding quTox for live victim support. The notes also state that the attackers will publish all stolen data on the Tor website if their demands are not met within three days.

The new version of Cuba ransomware indicates that the group will continue to pose a threat to organizations in the coming months, particularly those located in North America.

There is currently no free decryption tool for Cuba ransomware, so organizations should be cautious and implement ransomware security best practices to protect themselves

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS