“Tropical Scorpius”, a group of threat actors associated with the Cuba Ransomware (aka COLDDRAW), was recently observed deploying the malware with previously undocumented tactics, techniques, and procedures (TTPs), including a new remote access Trojan called ROMCOM RAT and a new local privilege escalation tool.
The Cuba Ransomware family is a double extortion ransomware group and was first sighted in late 2019. The threat actors behind the ransomware resumed their activity in November 2021 and have been regularly changing the ransomware’s TTPs and upgrading its capabilities. These changes enable it to fly under the radar and move laterally across compromised networks. As a potential prominent threat, understanding this malware and how to avoid it is crucial to your organization’s security.
In our Cuba Ransomware lab, you will learn all about this growing threat. You will review its technical analysis, become familiar with its techniques, and learn the steps to take to avoid it.