Cuba Ransomware Continues to Evolve with Dangerous Backdoor | |
The Cuba ransomware group, known for its Russian-speaking operators, continues to advance its tactics, posing a significant threat to organizations across the globe. Recent research by Kaspersky has unveiled new versions of the Cuba group’s malware, specifically the BurntCigar malware, showcasing the group’s ongoing evolution. Kaspersky’s investigation began after an incident was detected on a client’s system in December. The attack led to the deployment of a sophisticated backdoor called “komar65” or BugHatch. This backdoor operates in process memory, executing embedded shellcode and connecting to a command-and-control server. It can receive instructions to download additional software, including notorious tools like Cobalt Strike Beacon and Metasploit. The use of Veeamp in the attack strongly suggests Cuba’s involvement. for more details please visit our website :https://www.secuzine.com/cuba-ransomware-continues-to-evolve-with-dangerous-backdoor/ ![]() | |
Related Link: Click here to visit item owner's website (0 hit) | |
Target State: Texas Target City : Austin Last Update : Jun 13, 2025 3:36 AM Number of Views: 18 | Item Owner : secuzine Contact Email: Contact Phone: (None) |
Friendly reminder: Click here to read some tips. |