Ransomware group profile · #67 by claimed victims
Cuba ransomwarealso Colddraw
The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted.<br> <br> Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site.<br> <br> According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in 2023, there were indications that the developer behind the Cuba ransomware speaks Russian.<br> <br> The ransomware operators use a double extortion approach, and following the USA, in August 2022, it was believed that the Cuba ransomware group had compromised 101 entities, demanding $145 million in ransom payments and receiving up to $60 million.<br> <br> The group used a similar set of TTPs, with only a slight change each year, as they generally consist of LOLBins (executables that are part of the operating system and can be exploited to support an attack), exploits, off-the-shelf and custom malware, as well as intrusion tools like Cobalt Strike and Metasploit.<br> <br> In 2022, the group allegedly developed a relationship with operators of the Industrial Spy market, using their platform as a means of data leakage.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs
Victimology
Who Cuba claims to have breached, from 103 leak-site posts recorded by VULONE.
Claims per month last 12 months
Top sectors
Top countries
Latest claimed victims 12 most recent
| Victim | Sector | Country | Claimed |
|---|---|---|---|
| dms-imaging dms.com | Healthcare | FR | 1 Feb 2024 |
| deknudtframes.be deknudtframes.be | Manufacturing | BE | 22 Jan 2024 |
| diagnostechs diagnostechs.com | Healthcare | — | 14 Nov 2023 |
| portadelaidefc portadelaidefc.com.au | Retail & E-Commerce | AU | 13 Nov 2023 |
| panaya panaya.com | Technology | — | 7 Nov 2023 |
| prime-art | Retail & E-Commerce | — | 7 Nov 2023 |
| Newconcepttech | Technology | — | 23 Oct 2023 |
| mountstmarys | Education | — | 10 Oct 2023 |
| co.rock.wi.us co.rock.wi.us | Government & Defense | US | 3 Oct 2023 |
| goldmedalbakery goldmedalbakery.com | Agriculture and Food Production | — | 19 Aug 2023 |
| hydrex.co.uk hydrex.co.uk | Energy & Utilities | GB | 31 Jul 2023 |
| txmplant.co.uk txmplant.co.uk | Manufacturing | GB | 31 Jul 2023 |
All 103 Cuba victims, searchable
Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.
Tactics, techniques and procedures
ATT&CK technique mapping for Cuba is in progress. Victimology, infrastructure status and leak-site tracking are live above.
Indicators, detections and the full playbook
Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.
Frequently asked
Is Cuba ransomware still active?
How many victims has Cuba claimed?
Which industries does Cuba target?
Which countries are most affected by Cuba?
Where does VULONE get Cuba victim data?
Other ransomware groups
Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].