← All ransomware groups

Ransomware group profile · #67 by claimed victims

Cuba ransomwarealso Colddraw

The Cuba Ransomware, also known as Colddraw Ransomware, was first identified in the threat landscape in 2019 and built a relatively small but selected list of victims. The group is also known as Fidel Ransomware, due to a characteristic marker placed at the beginning of all encrypted files. This file marker is used as an indicator for the ransomware and its decoder that the file has been encrypted.<br> <br> Despite its name and the Cuban nationalist style on its leak site, it is difficult to assert any connection or affiliation with the Republic of Cuba. The group has been linked to a Russian-language threat actor by Profero researchers due to some details of incorrect translation they discovered, as well as the discovery of a 404 page containing text in Russian on the threat actor's own leak site.<br> <br> According to BlackBerry, based on the analysis of the code strings used in the campaign analyzed in 2023, there were indications that the developer behind the Cuba ransomware speaks Russian.<br> <br> The ransomware operators use a double extortion approach, and following the USA, in August 2022, it was believed that the Cuba ransomware group had compromised 101 entities, demanding $145 million in ransom payments and receiving up to $60 million.<br> <br> The group used a similar set of TTPs, with only a slight change each year, as they generally consist of LOLBins (executables that are part of the operating system and can be exploited to support an attack), exploits, off-the-shelf and custom malware, as well as intrusion tools like Cobalt Strike and Metasploit.<br> <br> In 2022, the group allegedly developed a relationship with operators of the Industrial Spy market, using their platform as a means of data leakage.<BR>Source: https://github.com/crocodyli/ThreatActors-TTPs

Active First seen Feb 2021
103Victims claimed on leak sites
0Victims in the last 30 days
0Victims in the last 90 days
7Countries hit
4Leak-site URLs tracked, 0 online
1 Feb 2024Latest claim recorded

Victimology

Who Cuba claims to have breached, from 103 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 0Apr 2026: 0AprMay 2026: 0Jun 2026: 0Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Manufacturing17
Technology14
Professional Services12
Financial Services11
Government & Defense7
Healthcare6
Transportation5
Retail & E-Commerce4

Top countries

United Kingdom3
United States2
Taiwan1
Belgium1
Australia1
Lithuania1
France1

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
dms-imaging dms.com Healthcare FR 1 Feb 2024
deknudtframes.be deknudtframes.be Manufacturing BE 22 Jan 2024
diagnostechs diagnostechs.com Healthcare 14 Nov 2023
portadelaidefc portadelaidefc.com.au Retail & E-Commerce AU 13 Nov 2023
panaya panaya.com Technology 7 Nov 2023
prime-art Retail & E-Commerce 7 Nov 2023
Newconcepttech Technology 23 Oct 2023
mountstmarys Education 10 Oct 2023
co.rock.wi.us co.rock.wi.us Government & Defense US 3 Oct 2023
goldmedalbakery goldmedalbakery.com Agriculture and Food Production 19 Aug 2023
hydrex.co.uk hydrex.co.uk Energy & Utilities GB 31 Jul 2023
txmplant.co.uk txmplant.co.uk Manufacturing GB 31 Jul 2023

All 103 Cuba victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Cuba is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Cuba ransomware still active?
Cuba is tracked as active. The most recent leak-site claim VULONE recorded is dated 1 February 2024.
How many victims has Cuba claimed?
VULONE has recorded 103 leak-site victim claims attributed to Cuba since February 2021, across 7 countries and 13 sectors.
Which industries does Cuba target?
The sectors most often named on the Cuba leak site are Manufacturing, Technology, Professional Services.
Which countries are most affected by Cuba?
Most Cuba victims recorded by VULONE are located in United Kingdom, United States, Taiwan.
Where does VULONE get Cuba victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].