Security News > 2022 > August > Hacker uses new RAT malware in Cuba Ransomware attacks
![Hacker uses new RAT malware in Cuba Ransomware attacks](/static/build/img/news/hacker-uses-new-rat-malware-in-cuba-ransomware-attacks-medium.jpg)
A member of the Cuba ransomware operation is employing previously unseen tactics, techniques, and procedures, including a novel RAT and a new local privilege escalation tool.
The threat actor was named 'Tropical Scorpius' by researchers at Palo Alto Networks Unit 42 and is likely an affiliate of the Cuba ransomware operation.
Tropical Scorpius marks a shift to new tactics, making the Cuba operation potentially more dangerous and intrusive.
Tropical Scorpius TTPs. The threat actor, Tropical Scorpius, uses the standard Cuba ransomware payload, which has remained largely unchanged since the operation launched in 2019.
Unit 42 noticed that Tropical Scorpius compiled a new version of ROMCOM and uploaded it for testing on VirusTotal on June 20, 2022, which pointed to the same C2 address.
The appearance of Tropical Scorpius and its new TTPs indicates that Cuba ransomware is evolving into a greater threat, even if the particular RaaS isn't the most prolific in terms of the number of victims.
News URL
Related news
- Andariel Hackers Target South Korean Institutes with New Dora RAT Malware (source)
- Hackers Use MS Excel Macro to Launch Multi-Stage Malware Attack in Ukraine (source)
- Pakistani Hackers Use DISGOMOJI Malware in Indian Government Cyber Attacks (source)
- Ratel RAT targets outdated Android phones in ransomware attacks (source)
- Rafel RAT targets outdated Android phones in ransomware attacks (source)
- Hackers attack HFS servers to drop malware and Monero miners (source)
- Microsoft links Scattered Spider hackers to Qilin ransomware attacks (source)
- North Korean Hackers Shift from Cyber Espionage to Ransomware Attacks (source)
- US offers $10M for tips on DPRK hacker linked to Maui ransomware attacks (source)
- U.S. DoJ Indicts North Korean Hacker for Ransomware Attacks on Hospitals (source)