ATT&CKReferencesMcAfee Cuba April 2021

McAfee Cuba April 2021

Roccio, T., et al. (2021, April). Technical Analysis of Cuba Ransomware. Retrieved June 18, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples23

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareCuba

Cuba can query service status using QueryServiceStatusEx function.

T1016
System Network Configuration Discovery
MalwareCuba

Cuba can retrieve the ARP cache from the local system by using GetIpNetTable.

T1027
Obfuscated Files or Information
MalwareCuba

Cuba has used multiple layers of obfuscation to avoid analysis, including its Base64 encoded payload.

T1027.002
Software Packing
MalwareCuba

Cuba has a packed payload when delivered.

T1036.005
Match Legitimate Resource Name or Location
MalwareCuba

Cuba has been disguised as legitimate 360 Total Security Antivirus and OpenVPN programs.

T1049
System Network Connections Discovery
MalwareCuba

Cuba can use the function GetIpNetTable to recover the last connections to the victim's machine.

T1056.001
Keylogging
MalwareCuba

Cuba logs keystrokes via polling by using GetKeyState and VkKeyScan functions.

T1057
Process Discovery
MalwareCuba

Cuba can enumerate processes running on a victim's machine.

T1059.001
PowerShell
MalwareCuba

Cuba has been dropped onto systems and used for lateral movement via obfuscated PowerShell scripts.

T1059.003
Windows Command Shell
MalwareCuba

Cuba has used cmd.exe /c and batch files for execution.

T1070.004
File Deletion
MalwareCuba

Cuba can use the command cmd.exe /c del to delete its artifacts from the system.

T1083
File and Directory Discovery
MalwareCuba

Cuba can enumerate files by using a variety of functions.

T1105
Ingress Tool Transfer
MalwareCuba

Cuba can download files from its C2 server.

T1106
Native API
MalwareCuba

Cuba has used several built-in API functions for discovery like GetIpNetTable and NetShareEnum.

T1134
Access Token Manipulation
MalwareCuba

Cuba has used SeDebugPrivilege and AdjustTokenPrivileges to elevate privileges.

T1135
Network Share Discovery
MalwareCuba

Cuba can discover shared resources using the NetShareEnum API call.

T1486
Data Encrypted for Impact
MalwareCuba

Cuba has the ability to encrypt system data and add the ".cuba" extension to encrypted files.

T1489
Service Stop
MalwareCuba

Cuba has a hardcoded list of services and processes to terminate.

T1543.003
Windows Service
MalwareCuba

Cuba can modify services by using the OpenService and ChangeServiceConfig functions.

T1564.003
Hidden Window
MalwareCuba

Cuba has executed hidden PowerShell windows.

T1614.001
System Language Discovery
MalwareCuba

Cuba can check if Russian language is installed on the infected machine by using the function GetKeyboardLayoutList.

T1620
Reflective Code Loading
MalwareCuba

Cuba loaded the payload into memory using PowerShell.

T1680
Local Storage Discovery
MalwareCuba

Cuba can enumerate local drives, disk type, and disk free space.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.