https://cairoict.com/trade-visitor-registration/ https://cairoict.com/trade-visitor-registration/ https://cairoict.com/trade-visitor-registration/
الخميس, 16 أبريل, 2026
سياسة الخصوصية
من نجن
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English
Techno fin
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English

Cuba ransomware deploys new malware

by تكنو فن
سبتمبر 20, 2023
Reading Time: 3 mins read
A A
malware

Transparency smart phone with ransomware attack warning sign.

Kaspersky has unveiled research into the activities of the notorious ransomware group known as Cuba. This cybercriminal gang has recently deployed malware that evaded advanced detection, and targeted organizations worldwide, leaving a trail of compromised companies across various industries.

In December 2022, Kaspersky detected a suspicious incident on a client’s system, uncovering three dubious files. These files triggered a sequence of actions that lead to loading the komar65 library, also known as BUGHATCH.

BUGHATCH is a sophisticated backdoor that deploys in process memory. It executes an embedded block of shellcode within the memory space allocated to it using the Windows API, which includes various functions. Subsequently, it connects to a Command and Control (C2) server, awaiting further instructions. It can receive commands to download software like Cobalt Strike Beacon and Metasploit. The use of Veeamp in the attack strongly suggests Cuba’s involvement.

Notably, the PDB file references the “komar” folder, a Russian word for “mosquito”, indicating the potential presence of Russian-speaking members within the group. Further analysis by Kaspersky unveiled additional modules distributed by the Cuba group, enhancing the malware’s functionality. One such module is responsible for collecting system information, which is then sent to a server via HTTP POST requests.

Continuing their investigation, Kaspersky uncovered new malware samples attributed to the Cuba group on VirusTotal. Some of these samples had managed to evade detection by other security vendors. These samples represent fresh iterations of the BURNTCIGAR malware, employing encrypted data to evade antivirus detection.

 

“Our findings underscore the importance of access to the latest reports and threat intelligence. As ransomware gangs like Cuba evolve and refine their tactics, staying ahead of the curve is crucial to effectively mitigate potential attacks. With the ever-changing landscape of cyber threats, knowledge is the ultimate defense against emerging cybercriminals,” says Gleb Ivanov, a cybersecurity expert at Kaspersky.

Cuba is a single-file ransomware strain, challenging to detect due to its operation without additional libraries. This Russian-speaking group is known for its extensive reach and targets industries such as retail, finance, logistics, government, and manufacturing across North America, Europe, Oceania, and Asia. They employ a mix of public and proprietary tools, regularly updating their toolkit and using tactics like BYOVD (Bring Your Own Vulnerable Driver).

A hallmark of their operation is altering compilation timestamps to mislead investigators.

For instance, some samples found in 2020 had a compilation date of June 4, 2020, while the timestamps on newer versions were displayed as originating from June 19, 1992. Their unique approach involves not just encrypting data but also tailoring attacks to extract sensitive information, such as financial documents, bank records, company accounts, and source code. Software development firms are notably at risk. Despite being in the spotlight for some time, this group remains dynamic, constantly refining their techniques.

شارك هذا الموضوع

  • المشاركة على WhatsApp (فتح في نافذة جديدة) WhatsApp
  • المشاركة على Telegram (فتح في نافذة جديدة) Telegram
  • المزيد
  • تدوينة
  • Tweet

مرتبط

RelatedPosts

“Raising Good Gamers” is a global program that teaches parents the secrets of video games”

Google Launches “Personal Intelligence” Feature for Gemini Users Across the Arab Region

LG Expands Partnership with WATCH IT to Boost Arabic Content Across LG Channels and webOS

Tags: malware

Related Posts

Raising Good Gamers
English

“Raising Good Gamers” is a global program that teaches parents the secrets of video games”

أبريل 15, 2026
“Gemini”
English

Google Launches “Personal Intelligence” Feature for Gemini Users Across the Arab Region

أبريل 15, 2026
LG Channels
English

LG Expands Partnership with WATCH IT to Boost Arabic Content Across LG Channels and webOS

أبريل 15, 2026
سي شور هايد بارك Hyde Park
English

Hyde Park Develops New “Shore Residences” Phase in Seashore Project in Ras El Hekma

أبريل 15, 2026
Load More

آخر الأخبار

Raising Good Gamers

“Raising Good Gamers” is a global program that teaches parents the secrets of video games”

أبريل 15, 2026
“Gemini”

Google Launches “Personal Intelligence” Feature for Gemini Users Across the Arab Region

أبريل 15, 2026
Facebook Messenger

بكرة آخر يوم.. ميتا تقفل موقع Messenger رسميًا

أبريل 15, 2026
صفقة ضخمة.. أحمد طارق يعزز ملكيته في “المطورون العرب” بمئات الملايين من الأسهم

صفقة ضخمة.. أحمد طارق يعزز ملكيته في “المطورون العرب” بمئات الملايين من الأسهم

أبريل 15, 2026
LG Channels

LG Expands Partnership with WATCH IT to Boost Arabic Content Across LG Channels and webOS

أبريل 15, 2026
No Result
View All Result
contact us: info@techno-fin.com Dubai:0553028804 Cairo:01150009990

Follow Us

All rights reserved to www.techno-fin.com, UAE, Sheikh Zayed Road, City Tower 2, 18th floor, office 1801
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English