[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/cuba-ransomware-tropical-scorpius/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/ "Threat Actor Groups")
* [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/ "Ransomware")  
  [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)

# Novel News on Cuba Ransomware: Greetings From Tropical Scorpius

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 19 min read  
Related Products  
[![Advanced DNS Security icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced DNS Security](https://unit42.paloaltonetworks.com/product-category/advanced-dns-security/ "Advanced DNS Security")[![Advanced Threat Prevention icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced Threat Prevention](https://unit42.paloaltonetworks.com/product-category/advanced-threat-prevention/ "Advanced Threat Prevention")[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")[![Cloud-Delivered Security Services icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Cloud-Delivered Security Services](https://unit42.paloaltonetworks.com/product-category/cloud-delivered-security-services/ "Cloud-Delivered Security Services")[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Anthony Galiette](https://unit42.paloaltonetworks.com/author/anthony-galiette/)
  * [Daniel Bunce](https://unit42.paloaltonetworks.com/author/daniel-bunce/)
  * [Doel Santos](https://unit42.paloaltonetworks.com/author/doel-santos/)
  * [Shawn Westfall](https://unit42.paloaltonetworks.com/author/shawn-westfall/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:August 9, 2022

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Ransomware](https://unit42.paloaltonetworks.com/category/ransomware/)
  * [Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Cuba Ransomware](https://unit42.paloaltonetworks.com/tag/cuba-ransomware/)
  * [Investigation and Response](https://unit42.paloaltonetworks.com/tag/investigation-and-response/)
  * [ROMCOM RAT](https://unit42.paloaltonetworks.com/tag/romcom-rat/)
  * [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/)
  * [Tropical Scorpius](https://unit42.paloaltonetworks.com/tag/tropical-scorpius/)
  * [UNC2596](https://unit42.paloaltonetworks.com/tag/unc2596/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius/?pdf=download&lg=en&_wpnonce=40dbae5d0f "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius/?pdf=print&lg=en&_wpnonce=40dbae5d0f "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Novel%20News%20on%20Cuba%20Ransomware:%20Greetings%20From%20Tropical%20Scorpius&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fcuba-ransomware-tropical-scorpius%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcuba-ransomware-tropical-scorpius%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcuba-ransomware-tropical-scorpius%2F&title=Novel%20News%20on%20Cuba%20Ransomware:%20Greetings%20From%20Tropical%20Scorpius "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcuba-ransomware-tropical-scorpius%2F&text=Novel%20News%20on%20Cuba%20Ransomware:%20Greetings%20From%20Tropical%20Scorpius "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fcuba-ransomware-tropical-scorpius%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Novel%20News%20on%20Cuba%20Ransomware:%20Greetings%20From%20Tropical%20Scorpius%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fcuba-ransomware-tropical-scorpius%2F "Share in Mastodon")

## **Executive Summary**

Beginning in early May 2022, Unit 42 observed a threat actor deploying Cuba Ransomware using novel tools and techniques. Using [our naming schema](https://unit42.paloaltonetworks.com/unit-42-threat-group-naming-update/), Unit 42 tracks the threat actor as Tropical Scorpius.

Here, we start with an overview of the ransomware and focus on an evolution of behavior observed leading up to deployment of Cuba Ransomware. While this behavior was consistent for over a year, Unit 42 has observed some recent changes. This includes providing an overview of the ransomware's functionality and algorithms, as well as covering the technical details of the tactics, techniques and procedures (TTPs) used by Tropical Scorpius. Specifically, this involves:

* A new malware family that Unit 42 tracks as ROMCOM RAT.
* A weaponized local privilege escalation exploit to SYSTEM.
* A new Kerberos tool that Unit 42 tracks as KerberCache.
* A kernel driver for targeting security products.
* Identifying the use of the ZeroLogon hacktool.

Palo Alto Networks customers receive protections from the threats described in this blog through our [Cloud-Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions), namely [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention). Customers also receive protections from [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) and [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire) malware analysis.

If you think you may have been impacted by a cyber incident, the [Unit 42 Incident Response team](https://www.paloaltonetworks.com/unit42/respond/incident-response) is available 24/7/365. You can also take preventative steps by requesting any of our [cyber risk management services](https://www.paloaltonetworks.com/unit42/assess).

Full visualization of the techniques observed, relevant courses of action and indicators of compromise (IoCs) related to this report can be found in the [Unit 42 ATOM viewer.](https://unit42.paloaltonetworks.com/atoms/tropicalscorpius/)

|--------------------------------------------------------|----------------------------|
| Related Unit 42 Topics                                 | Ransomware                 |
| Names for threat actor group deploying Cuba Ransomware | Tropical Scorpius, UNC2596 |

## Tropical Scorpius Overview: How Cuba Ransomware Has Been Deployed

The Cuba Ransomware family first surfaced in December 2019. The threat actors behind this ransomware family have since changed their tactics and tooling to become a more prevalent threat in 2022. This ransomware has historically been distributed through [Hancitor](https://unit42.paloaltonetworks.com/hancitor-infections-cobalt-strike/), which is usually delivered through malicious attachments. Tropical Scorpius has also been observed exploiting vulnerabilities in [Microsoft Exchange Server,](https://unit42.paloaltonetworks.com/microsoft-exchange-server-attack-timeline/) including [ProxyShell](https://techcommunity.microsoft.com/t5/exchange-team-blog/proxyshell-vulnerabilities-and-your-exchange-server/ba-p/2684705) and [ProxyLogon](https://msrc-blog.microsoft.com/2021/03/16/guidance-for-responders-investigating-and-remediating-on-premises-exchange-server-vulnerabilities/).

This ransomware group uses double extortion alongside a leak site that exposes organizations that have allegedly been compromised (Figures 1a and 1b). That said, this group didn't have a leak site when first observed in 2019; we suspect the inspiration for adding one came from other ransomware groups such as [Maze](https://unit42.paloaltonetworks.com/threat-brief-maze-ransomware-activities/) and [REvil](https://unit42.paloaltonetworks.com/revil-threat-actors/). The Cuba Ransomware leak site also includes a paid section where the threat actors share leaks that were sold to an interested party.
![Screenshot of Cuba Ransomware leak site: "Cuba Ransomware welcomes you. This site contains information about companies that did not want to cooperate with us. Part of the information is for sale, part is freely available. have fun." The site includes images of Cuban revolutionaries and a section at the bottom offering free information about particular organizations.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image.png) Figure 1a. A screenshot from the leak site used by Cuba Ransomware, focused on the content the group makes freely available. ![A screenshot of the section of the Cuba Ransomware group's leak site where data is offered for sale. An organization is pictured along with an option to "view all."](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-1.png) Figure 1b. A screenshot of the section of the Cuba Ransomware group's leak site where data is offered for sale.

## Tropical Scorpius Victimology

The most recent [Unit 42 Ransomware Threat Report](https://start.paloaltonetworks.com/unit-42-ransomware-threat-report.html) includes observations of Cuba Ransomware impacting 33 organizations. As of July 2022, Tropical Scorpius has used Cuba Ransomware to impact 27 additional organizations across multiple vectors, such as Professional and Legal Services, State and Local Government, Manufacturing, Transportation and Logistics, Wholesale and Retail, Real Estate, Financial Services, Health Care, High Technology, Utilities and Energy, Construction, and Education. A total of 60 organizations were exposed by this ransomware gang on its leak site since the group first surfaced in 2019.

We suspect the number of victims is larger than the leak site shows since ransomware operators usually don't release the data publicly if the victim pays the ransom. That said, the [FBI says the Cuba Ransomware gang made at least $43.9 million](https://www.ic3.gov/Media/News/2021/211203-2.pdf) from ransom payments and has demanded at least $74 million.
:chart: Figure 2. Organizations appearing on the Cuba Ransomware leak site, distributed by industry.

We observed that this ransomware gang's leak site does not include as global a distribution of targeted organizations as other ransomware gangs operating right now. While leak sites don't reflect the actual number of victims impacted by this ransomware group, they still give us a general idea of a group's targets and objectives. We noticed that out of the 60 victims listed on the Cuba Ransomware leak site, 40 were located in the United States -- 66% of the total number of allegedly breached organizations. By contrast, only about 30% of the allegedly breached organizations on the [LockBit](https://unit42.paloaltonetworks.com/lockbit-2-ransomware/) leak site are located in the U.S.
![Geographic distributions of organizations targeted by Cuba Ransomware, according to the group's leak site. Highest concentration is in the United States, followed by Canada, Italy, Australia, and other countries around the world.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/chart-1.png) Figure 3. Geographic distribution of organizations targeted by Cuba Ransomware, according to the group's leak site.

## Industrial Spy and Tropical Scorpius

In May 2022, BleepingComputer [reported](https://www.bleepingcomputer.com/news/security/industrial-spy-data-extortion-market-gets-into-the-ransomware-game/) that the marketplace Industrial Spy was moving into the ransomware business. After emerging in April 2022, Industrial Spy became known as a site where threat actors can sign up to buy stolen data from breached companies. The extension into ransomware, while a related type of malicious activity, also appears to have a connection to Tropical Scorpius.
![Industrial Spy landing page - "Who owns the information, he owns the world." The site is split into three sections: Premium, general and free.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-2.png) Figure 4. Industrial Spy landing page.

BleepingComputer reports that the ransom note used by Industrial Spy ransomware bears substantial resemblance to a Cuba ransom note, with both notes containing the exact same contact information. It's worth mentioning that ransomware groups usually copy ransom notes from other groups for their own samples, but we believe there is more to this relationship.

Unit 42 observed a Cuba Ransomware payload used to encrypt the files on a compromised system, appending the .cuba extension to the files -- but then observed that the exfiltrated data was posted for sale on the Industrial Spy marketplace.

We are still unsure why the Tropical Scorpius threat actors decided to leverage the Industrial Spy marketplace rather than their own leak site; however, due to the findings published by BleepingComputer and this curious incident, we believe there is more involvement between the two than originally thought.

## Ransomware Functionality

While it is clear the Tropical Scorpius threat actors are constantly developing and updating their toolkit, the core Cuba Ransomware payload has remained roughly the same since its discovery in 2019. The cryptographic algorithms are still taken from WolfSSL's open source repository, specifically ChaCha for file encryption and RSA for key encryption.
![Code overlap between Cuba Ransomware and WolfSSL’s RSA encrypt functionality. The first line in the snippet is v14 = a3;](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-3.png) Figure 5. Code overlap between Cuba Ransomware and WolfSSL's RSA encrypt functionality.

Similarly to most ransomware families, Cuba Ransomware encrypts files differently depending on their size. If the file is less than 0x200000 bytes in length, the entire file is encrypted. If not, Cuba Ransomware encrypts the files in chunks of 0x100000 bytes, with the break in between the encrypted chunks differing based on the overall size. For example, a file with a size between 0x200000 bytes and 0xA00000 bytes will be modified in blocks of 0x400000 bytes until the file's end.
![Determination of chunk spacing prior to file encryption. The first line in the snippet is \*a4 = 0xFFFFFFF;](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-4.png) Figure 6. Determination of chunk spacing prior to file encryption.

|----------------------------------|-------------|---------------|
| File Size                        | Chunk Size  | Chunk Spacing |
| Less than 0x200000               | Entire Size | N/A           |
| Between 0x200000 \& 0xA00000     | 0x100000    | 0x400000      |
| Between 0xA00000 \& 0x3200000    | 0x100000    | 0x800000      |
| Between 0x3200000 \& 0xC800000   | 0x100000    | 0x1000000     |
| Between 0xC800000 \& 0x280000000 | 0x100000    | 0xC800000     |
| Greater than 0x280000000         | 0x100000    | 0x1F400000    |

*Table 1. Chunk spacing based on file sizes within Cuba Ransomware.*

Each encrypted file is also prepended with an initial 1024-byte header, containing the magic value FIDEL.CA (likely in reference to Fidel Castro, following the Cuba theme), followed by an RSA-4096 encrypted block containing the file-specific ChaCha key and nonce. After successfully encrypting a file, the extension .cuba is appended to the filename.
![FIDEL.CA magic value followed by encrypted RSA blob.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-5.png) Figure 7. FIDEL.CA magic value followed by encrypted RSA blob.

As discussed by [Trend Micro](https://www.trendmicro.com/en_us/research/22/f/cuba-ransomware-group-s-new-variant-found-using-optimized-infect.html), the developers of Cuba Ransomware have built onto the list of targeted processes and services that will be terminated on runtime, as well as increasing the number of directories and extensions to avoid encrypting.

**Targeted processes and services:** MySQL  
MySQL82SQLSERVERAGENT  
MSSQLSERVER  
SQLWriter  
SQLTELEMETRY  
MSDTC  
SQLBrowser  
sqlagent.exe  
sqlservr.exe  
sqlwriter.exe  
sqlceip.exe  
msdtc.exe  
sqlbrowser.exe  
vmcompute  
vmms  
vmwp.exe  
vmsp.exe  
outlook.exe  
MSExchangeUMCR  
MSExchangeUM  
MSExchangeTransportLogSearch  
MSExchangeTransport  
MSExchangeThrottling  
MSExchangeSubmission  
MSExchangeServiceHost  
MSExchangeRPC  
MSExchangeRepl  
MSExchangePOP3BE  
MSExchangePop3  
MSExchangeNotificationsBroker  
MSExchangeMailboxReplication  
MSExchangeMailboxAssistants  
MSExchangeIS  
MSExchangeIMAP4BE  
MSExchangeImap4  
MSExchangeHMRecovery  
MSExchangeHM  
MSExchangeFrontEndTransport  
MSExchangeFastSearch  
MSExchangeEdgeSync  
MSExchangeDiagnostics  
MSExchangeDelivery  
MSExchangeDagMgmt  
MSExchangeCompliance  
MSExchangeAntispamUpdate  
Microsoft.Exchange.Store.Worker.exe

**Avoided directories:**  
\\windows\\  
\\program files\\microsoft office\\  
\\program files (x86)\\microsoft office\\  
\\program files\\avs\\  
\\program files (x86)\\avs\\  
\\$recycle.bin\\  
\\boot\\  
\\recovery\\  
\\system volume information\\  
\\msocache\\  
\\users\\all users\\  
\\users\\default user\\  
\\users\\default\\  
\\temp\\  
\\inetcache\\  
\\google\\

**Avoided extensions:**  
.exe  
.dll  
.sys  
.ini  
.lnk  
.vbm  
.cuba

Another major update can be found within the ransom note dropped by the ransomware; rather than rely solely on their Tor site, they are also offering communication via TOX, which is slowly becoming more popular among ransomware groups due to its secure messaging functionality.
![Sample ransom note. It begins: "Greetings! Unfortunately we have to report you that your company were compromised. All your files were encrypted and you can't restore them without our private key. Trying to restore it without our help may cause complete loss of your data. Also we researched whole your corporate network and downloaded all your sensitive data to our servers. If we will not get any contact from you in 3 next days we will public it in our news site. You can fine it there." What follows are details of how to get in touch with the threat actors.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/Figure-8.png) Figure 8. Ransom note dropped by Cuba Ransomware group.

## Defense Evasion

Unit 42 observed Tropical Scorpius prior to the deployment of ransomware, using some interesting tools and techniques to evade detection and move around in the compromised environment.

Tropical Scorpius leveraged a dropper that writes a kernel driver to the file system called ApcHelper.sys. This targets and terminates security products. The dropper was not signed, however, the kernel driver was signed using the certificate found in the [LAPSUS](https://unit42.paloaltonetworks.com/lapsus-group/) NVIDIA leak.
![Kernel driver digital signature. The screenshot shows the signer as NVIDIA corp and also shows the serial number.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-7.png) Figure 9. Kernel driver digital signature.

Upon executing the kernel driver dropper/loader, the kernel dropper uses multiple Windows APIs for finding the resource section and loading the resource type name called Driver. This is an embedded PE file and is the driver that will ultimately be written to the file system in subsequent API calls.
![Kernel dropper resource section. The screenshot shows Driver \> 143 : 2052.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-8.png) Figure 10. Kernel dropper resource section.

After the kernel driver drops onto the file system, the loader will first run a deletion command argument via cmd.exe for the file path.

![After the kernel driver drops onto the file system, the loader will first run a deletion command argument via cmd.exe for the file path.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/cmdImage.png)

After this, it will create a new service using cmd.exe and run the argument below to set up a service for the kernel driver.

![After this, it will create a new service using cmd.exe and run the argument below to set up a service for the kernel driver.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-10.png)

Then the loader copies the kernel driver responsible for terminating security products onto the file system.

![Then the loader copies the kernel driver responsible for terminating security products onto the file system.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-11.png)

The core functionality of the kernel driver dropped and loaded is to resolve additional kernel APIs for performing functionality and targeting a list of security products for termination.

The additional APIs are resolved using a string constant for the desired API name; each Windows API below is used in a function call to MmGetSystemRoutineAddress for returning a pointer to the function. Below is a list of additional kernel APIs resolved that were found within the sample.
![Kernel driver runtime APIs. These were found within the Cuba ransomware sample.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-12.png) Figure 11. Kernel driver runtime APIs.

The list of security products targeted overlaps with the list of targets previously observed in the tool called "BURNTCIGAR" as discussed by [Mandiant](https://www.mandiant.com/resources/unc2596-cuba-ransomware). This particular kernel driver is a variant of what Mandiant observed.
![Security products targeted. This list overlaps the list of targets previously observed in the tool called "BURNTCIGAR" as discussed by Mandiant.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-13.png) Figure 12. Security products targeted.

After the additional APIs are resolved, the process of targeting security products begins (products targeted are in Figure 12 above). A do-while loop is set up (loop is shown in Figure 13 below) with the objective of checking the processes running on the system to see if they match an item from the security products targeted. This naming check is performed by looking up each ThreadID and calling the function PsLookupThreadByThreadId, which will be used to find a pointer to the [ETHREAD](https://docs.microsoft.com/en-us/windows-hardware/drivers/kernel/eprocess) structure of the thread. The ETHREAD structure is a kernel object maintaining various references to important process/thread structures and objects needed by the operating system for tasking and execution by the CPU. The pointer to ETHREAD that is returned is used in the function PsIsThreadTerminating to make sure a thread is not terminating.

Then if a thread object exists, to find the process the thread belongs to, the function PsGetThreadProcess is used and the returned value is PEPROCESS. [PEPROCESS](<https://www.vergiliusproject.com/kernels/x64/Windows%2010%20%7C%202016/2110%2021H2%20(November%202021%20Update)/_EPROCESS>) is a kernel object representation of a process object which maintains pointers to where process-related information is stored. If PEPROCESS does exist for the associated thread, the ImageFileName offset is then assigned to a variable in the instance of the decompiled output; this is the variable named "v3" in Figure 13. The variable "v3" will then have the process image file name for the current thread/process in the loop, which could be any active process on a computer system.

The next part of performing the name check is the inner if-then statement that uses two parameters in the strstr function. The first parameter is the process image filename from the PEPROCESS structure's ImageFileName. The second parameter is a substring search of the security product's name to compare against the first parameter. (For example, does the name Sophos exist in the ImageFileName process name string?)

If there is a match, the next function, called sub\_140001BE0 (shown being called in Figure 13 below), will check if the status code of the thread is set to status pending. If this evaluates as true, then a subroutine will be called using ZwTerminateProcess for termination. The thread object will be dereferenced and the loop will continue to the next thread to start evaluating again for termination.
![Example of kernel driver decompiled. This shows the function sub\_140001BE0 being called.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-14.png) Figure 13. Example of kernel driver decompiled.

The change of tactics by Tropical Scorpius is to make use of the expired legitimate NVIDIA certificate, as well as use of their own driver targeting security products for termination. This is a noteworthy change compared to publicly observed exploitation of an undocumented IOCTL (Input/Output Control system calls) in previous versions of the vulnerable BURNTCIGAR driver.

## Local Privilege Escalation

The local privilege escalation tool leveraged by Tropical Scorpius was initially downloaded from the web hosting platform tmpfiles\[.\]org by using PowerShell's Invoke-WebRequest.

Unit 42 observed the actor leverage a binary that abused [CVE-2022-24521](https://nvd.nist.gov/vuln/detail/CVE-2022-24521), a vulnerability in the Common Log File System (CLFS). The exploit abused a logic bug in CLFS.sys, specifically in the CClfsBaseFilePersisted::LoadContainerQ() function. Malformed BLF files were used to corrupt the **pContainer** field of a container context object with a user-mode address to gain code execution. The code execution was used to steal the System token and elevate privileges. A detailed write-up of this vulnerability and the exploitation strategy was [provided](https://www.pixiepointsecurity.com/blog/nday-cve-2022-24521.html) by Sergey Kornienko of PixiePoint Security on April 25, 2022.

The Tropical Scorpius threat actor likely used this post as a guide to build the exploit since the exploitation strategy used is identical to what Sergey described, including the pipe attributes heap exploitation method to spray the heap.

This technique was [covered](https://www.sstic.org/media/SSTIC2020/SSTIC-actes/pool_overflow_exploitation_since_windows_10_19h1/SSTIC2020-Article-pool_overflow_exploitation_since_windows_10_19h1-bayet_fariello.pdf) in detail by Corentin Bayet and Paul Fariello of Synactiv at the Symposium on Information and Communications Technology Security (SSTIC) in 2020.

## Ticket to Lateral Movement

The Tropical Scorpius threat actor leveraged various tools for the initial system reconnaissance. ADFind and Net Scan were downloaded from the web hosting platform tmpfiles\[.\]org by using PowerShell's Invoke-WebRequest. Both tools were dropped onto the same system with shortened names to obscure their purpose.

Credential preparation and collection on lower-privilege systems was performed using a PowerShell-based script, GetUserSPNs.ps1. This particular script was observed on three different systems, where it identified user accounts being used as service accounts. The threat actor used this process to pinpoint accounts worth targeting for their associated Active Directory Kerberos ticket, in order to collect and crack the Kerberos ticket offline via the technique called [Kerberoasting](https://attack.mitre.org/techniques/T1558/003/).

Additional activity related to credential theft was observed approximately one week after the use of **GetUserSPNs.ps1**, with the observation of Mimikatz on a user's workstation being written into the user's document folder as a zipped file. Mimikatz is a well-known credential theft tool that contains various options for targeting parts of the operating system where credentials can potentially be found.

Around the time that Mimikatz was observed, a custom hacktool was observed on another workstation. This tool, intended for extracting cached Kerberos tickets from a host's LSASS memory, was dropped into a user's documents folder.

Unit 42 is naming the Kerberos tool used by Tropical Scorpius in terms of its overall objective: KerberCache. A screenshot of the tool's output was taken, displaying the parsed data the tool generates (Figure 14).
![Unit 42 is naming the Kerberos tool used by Tropical Scorpius in terms of its overall objective: KerberCache. A screenshot of the tool’s output was taken, displaying the parsed data the tool generates, as shown here.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-15.png) Figure 14. KerberCache ticket extraction example.

Under the hood, KerberCache will call the API LsaConnectUntrusted to get a handle used for subsequent calls. Following the returned handle, the call to LsaLookupAuthenticationPackage is then given the package named Kerberos along with the handle from the previous API call to LsaConnectUntrusted. If the function succeeds, it will call the API LsaCallAuthenticationPackage. Below (Figure 15) is a snippet of the function's flow once called and the decompiled formatting and parsing takes place.
![Ticket parsing decompiled example. This is a snippet of the function's flow once called and the decompiled formatting and parsing takes place.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-16.png) Figure 15. Ticket parsing decompiled example.

Upon successful retrieval of cached Kerberos tickets, the ticket will be passed to a function for base64-encoding the data and will be written to the current working directory in which the tool was executed. The naming convention output for the tool can be broken into the following sections: \[user@servername\]\_\[encryption\_type\].\[ticket\_number\].kirbi. The actual ticket naming convention, when written to the file system, appears as the following example output: krbtgt@CORP.INTERNAL\_18.0.kirbi.
![Ticket encoding decompiled example. The naming convention output for the tool can be broken into the following sections: \[user@servername\]\_\[encryption\_type\].\[ticket\_number\].kirbi](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-17.png) Figure 16. Ticket encoding decompiled example.

## To Domain Admin

The Domain Admin tool leveraged by Tropical Scorpius was initially downloaded from the web hosting platform tmpfiles\[.\]org by using PowerShell's Invoke-WebRequest. The sample was packed using the Anti-VM features of Themida, a well-known commercial packing tool. It was also masquerading as the filename Filezilla.

Upon execution, if running in a virtualized environment, the packer will display the following message:
![Themida Anti-VM example. The screenshot shows an error box that reads, "Sorry, this application cannot run under a Virtual Machine."](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-18.png) Figure 17. Themida Anti-VM example.

The unique commands associated with the hacktool provide high confidence Zero.exe is ZeroLogon hacktool. The ZeroLogon hacktool is used to abuse [CVE-2020-1472](https://nvd.nist.gov/vuln/detail/cve-2020-1472) to gain Domain Administrator (DA) privileges by requesting an NTLM hash from the domain controller.
![The ZeroLogon hacktool is used to abuse CVE-2020-1472 to gain Domain Administrator (DA) privileges by requesting an NTLM hash from the domain controller.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-19.png) Figure 18. ZeroLogon hacktool packed example.

It has been noted publicly that the ZeroLogon hacktool has gained popularity among other malware families as part of their attack chain in the crimeware space with overlap on intrusions related to [Qbot](https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/) and [Hancitor](https://thedfirreport.com/2021/11/01/from-zero-to-domain-admin/).

## Command and Control

Alongside the aforementioned tools, Unit 42 also discovered a custom remote access Trojan/backdoor containing a unique command and control (C2) protocol. Based on the strings within the binary as well as the functionality, we've opted to name it ROMCOM RAT.

ROMCOM RAT can be executed through the use of one of its two exports:

ServiceMain  
startWorker

Both exports lead to the execution of the same function; however, the difference is the string passed as a parameter: ServiceMain passes the string \_inet, while startWorker passes the string \_file. Based on this string alone, the flow of execution within the sample is completely different, with ServiceMain causing the sample to beacon out to its C2 server, and startWorker resulting in the sample opening a backdoor on the system and waiting for connections.

### ServiceMain Export

Upon execution of the ServiceMain export, ROMCOM will execute the following command line:

C:\\\\Windows\\\\System32\\\\rundll32.exe  
C:\\\\Windows\\\\System32\\\\comDll.dll,startWorker

This will lead to the execution of the startWorker export, meaning both exports will be active on a machine, presuming ROMCOM was initially executed through a service.
![Execution of ROMCOM sample through rundll32.exe with startWorker argument.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-20.png) Figure 19. Execution of ROMCOM sample through rundll32.exe with startWorker argument.

From there, ROMCOM will gather system and user information, and attempt to send it to a hardcoded C2 server via the WinHTTP API. If this is successful, the response is parsed and dealt with accordingly.
![ICMP capabilities offered within ROMCOM. First line of snippet is doICMPRequests = 0;](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-21.png) Figure 20. ICMP capabilities offered within ROMCOM. ![Command handling of the packet received from C2. First line of snippet is menmove(\&v38, receivedData, 4096u164)](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-22.png) Figure 21. Command handling of the packet received from C2.

If the connection fails, ROMCOM attempts to connect to and communicate with the C2 server using ICMP requests. Using Windows API functions such as IcmpCreateFile() and IcmpSendEcho(), it will attempt to resend the system and user information to the server until a response is received. Once a response is received, it is parsed in the same way the HTTP response will be parsed.
![ICMP request functionality. Once a response is received, it is parsed in the same way the HTTP response will be parsed.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-23.png) Figure 22. ICMP request functionality.

If the fourth byte of the response is equal to 9, ROMCOM will sleep for 120,000 milliseconds. If the fourth byte is set to 5, the response will contain a size for followup data, and so memory is allocated before a second request is made to the C2, using either HTTP or ICMP depending on the last protocol in use.

The received data from this second request is then passed into a function that first connects to the local address 127.0.0\[.\]3 over a port between 5555 and 5600, and then sends the C2 received data. The function then returns, and then ROMCOM binds to 127.0.0\[.\]2:5555, where it will wait for a connection and forward any data received from that connection to its C2 server.

![The function then returns, and then ROMCOM binds to 127.0.0\[.\]2:5555, where it will wait for a connection and forward any data received from that connection to its C2 server.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-24.png) Figure 23. Connecting to local socket server hosted by ROMCOM startWorker process. This leads nicely into a discussion of the startWorker export.

### startWorker Export

The startWorker export passes the string \_file to the main function of ROMCOM, which results in the code executed by the ServiceMain export being skipped. Instead, startWorker begins by opening a socket object and attempting to bind to the IP 127.0.0\[.\]3, and the port 5555. However, if the port is already in use, ROMCOM will increment the port value and attempt to bind once again. This loop continues until ROMCOM has bound to an unused port, or until the port value reaches 5600, at which point it is set to 5554 and the loop restarts.

![Setting up local socket server. Comments highlight the startWorker export and 127\[.\]0\[.\]0\[.\]3](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-25.png) Figure 24. Setting up local socket server. Once ROMCOM has successfully bound to a port, it begins listening for an incoming connection -- this will be fulfilled by the process that executed the ServiceMain export. When an incoming connection is received, a thread will be spawned that will handle any requests from the connected client.

![Command handler. The list of accepted commands follows in Table 2.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-26.png) Figure 25. Command handler.

Table 2 can be seen below, containing the list of accepted commands and their purpose.

|---------------|--------------------------------------------------------------------------------------------------------|
| Command Value | Purpose                                                                                                |
| 1             | Return connected drive information                                                                     |
| 2             | Return file listings for specified directory                                                           |
| 3             | Start up a reverse shell under the name svchelper.exe within the %ProgramData% folder                  |
| 4             | Upload data to C2 as ZIP file, using IShellDispatch to copy files                                      |
| 5             | Download data and write to worker.txt in the %ProgramData% folder                                      |
| 6             | Delete a specified file                                                                                |
| 7             | Delete a specified directory                                                                           |
| 8             | Spawn a process with PID Spoofing                                                                      |
| 9             | Only handled by ServiceMain, received from C2 server and instructs the process to sleep for 120,000 ms |
| 10            | Iterate through running processes and gather process IDs                                               |

*Table 2. Supported backdoor commands and their functionality.*

Essentially, this particular execution structure results in the ROMCOM sample running as a service receiving commands via HTTP/ICMP requests to and from its C2 servers, before passing those commands on to the ROMCOM sample that was executed through rundll32.exe. The commands are executed, with the results passed back to the service-executed ROMCOM payload. Finally, the results are posted to the C2 server, either via an HTTP or ICMP request.

### ROMCOM 2.0

It appears that ROMCOM is under active development, as we were able to discover a similar sample uploaded to VirusTotal (VT) on June 20, 2022, that was communicating to the same C2 server.

The original sample was dated April 10, 2022, while this sample had a file header timestamp of May 28, 2022, and was ~400 kb larger. It shared the same startWorker and ServiceMain exports; however, it also contained a third export denoted as startInet. It is important to note the increase in debug strings found within the sample, which could indicate that the sample was caught by antivirus software prior to development completion; this theory is further supported by the VT uploader ID (22b3c7b0) having uploaded millions of files in the past, which rules out any one individual uploading it themselves.

Within this version, ServiceMain will execute the ROMCOM 2.0 sample twice, initially executing the startInet export, and then proceeding to execute the startWorker export. However, rather than simply calling CreateProcessA like the original ROMCOM sample, the developers have placed a larger focus on using COM objects for execution.
![Execution of startInet and startWorker exports.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-27.png) Figure 26. Execution of startInet and startWorker exports.

Each process is spawned as a task on the system, using a variety of COM interfaces offered by the Task Scheduler. ROMCOM 2.0 will first get the tasks root folder by calling ITaskService-\>GetFolder. It then deletes any existing tasks with the same name as the task that will be created using ITaskFolder-\>DeleteTask.

|-----------|-------------------------------------------------------------------|
| Task Name | Export                                                            |
| task7     | startInet                                                         |
| task6     | startWorker                                                       |
| task1     | startWorker -- if not already running when startInet is executing |

Table 3. Names of tasks registered through the Task Scheduler COM interfaces.

An empty task is created with ITaskService-\>NewTask, and the security principal is then modified using IPrincipal-\>put\_Id to set the identifier as NT AUTHORITY\\\\SYSTEM, using IPrincipal-\>LogonType to set the logon type to TASK\_LOGON\_INTERACTIVE\_TOKEN, and using IPrincipal-\>put\_RunLevel to set the run level as TASK\_RUNLEVEL\_HIGHEST.
![Task creation with SYSTEM privileges. An empty task is created with ITaskService-\>NewTask, and the security principal is then modified using IPrincipal-\>put\_Id to set the identifier as NT AUTHORITY\\SYSTEM, using IPrincipal-\>LogonType to set the logon type to TASK\_LOGON\_INTERACTIVE\_TOKEN, and using IPrincipal-\>put\_RunLevel to set the run level as TASK\_RUNLEVEL\_HIGHEST.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-28.png) Figure 27. Task creation with SYSTEM privileges.

A delay of 0 seconds is set for the task, using IRegistrationTrigger-\>PutDelay, indicated by the string PT0S, resulting in the task executing immediately upon creation.
![A delay of 0 seconds is set for the task, using IRegistrationTrigger-\>PutDelay, indicated by the string PT0S, resulting in the task executing immediately upon creation.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-29.png) Figure 28. Creation of task trigger, with delay set to 0 seconds.

Finally, an action is set for the task, with the action path set to rundll32.exe and the argument set to C:\\\\Windows\\\\system32\\\\mskms.dll,ARGUMENT, where ARGUMENT is either startWorker or startInet, depending on the export passed.
![Finally, an action is set for the task, with the action path set to rundll32.exe and the argument set to C:\\Windows\\system32\\mskms.dll,ARGUMENT, where ARGUMENT is either startWorker or startInet, depending on the export passed.](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-30.png) Figure 29. Creation of task action, resulting in rundll32.exe executing mskms.dll.

Once registered, the task is triggered, which results in execution of the ROMCOM 2.0 main functionality. This follows the same structure as the original sample, with the startInet process reaching out to a hardcoded C2 server and passing any responses to the startWorker process to handle accordingly. The developers have also expanded on the list of handled commands, adding 10 more alongside the existing 10 commands. These include downloading payloads specifically designed to take single or multiple screenshots of a system, as well as extracting a list of all installed programs to send back to the C2 (see the SCREENSHOOTER string reference shown in Figure 30).
![Tropical Scorpius, the developers of Cuba Ransomware, have expanded on the list of handled commands, adding 10 more alongside the existing 10 commands. These include downloading payloads specifically designed to take single or multiple screenshots of a system, as well as extracting a list of all installed programs to send back to the C2 (see the SCREENSHOOTER string reference shown in the image).](https://unit42.paloaltonetworks.com/wp-content/uploads/2022/08/word-image-31.png) Figure 30. Downloading the described SCREENSHOOTER payload.

|---------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Command Value | Purpose                                                                                                                                                                                      |
| 1             | Return connected drive information                                                                                                                                                           |
| 2             | Return file listings for specified directory                                                                                                                                                 |
| 3             | Start up a reverse shell under the name winconhost.exe within the %TMP% folder                                                                                                               |
| 4             | Upload data to C2 as ZIP file, using IShellDispatch to copy files                                                                                                                            |
| 5             | Download data and write to worker.txt in the %TMP% folder                                                                                                                                    |
| 6             | Delete a specified file                                                                                                                                                                      |
| 7             | Delete a specified directory                                                                                                                                                                 |
| 8             | Spawn a process with PID Spoofing                                                                                                                                                            |
| 9             | Only handled by startInet, received from C2 server and instructs the process to sleep for a random amount of time                                                                            |
| 10            | Get Process IDs of specific processes                                                                                                                                                        |
| 12            | Execute rundll32.exe %TMP%\\\\PhotoDirector.dll,startWorker single and upload %TMP%\\\\PhotoDirector.zip to C2 server (likely used to take a single screenshot)                              |
| 13            | Execute rundll32.exe %TMP%\\\\PhotoDirector.dll,startWorker                                                                                                                                  |
| 14            | Upload %TMP%\\\\PhotoDirector.zip to C2 server                                                                                                                                               |
| 15            | Retrieve all running processes and process IDs                                                                                                                                               |
| 16            | Get list of installed software by querying SOFTWARE\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Uninstall or SOFTWARE\\\\WOW6432Node\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Uninstall |
| 18            | Write received file SCREENSHOOTER to %TMP%\\\\PhotoDirector.dll                                                                                                                              |
| 19            | Create %TMP%\\\\BrowserData folder, and write received file to %TMP%\\\\BrowserData\\\\explorer.exe before executing                                                                         |
| 20            | Write received file to and spawn %TMP%\\\\win\_sshd.exe, described as FreeSSHd                                                                                                                |
| 21            | References plink.exe -ssh -pw AeM8soequ@ooNg -R 9999:4444 poncho@CombinedResidency.org\\n, however appears to only execute C:\\\\Program Files (x86)\\\\freeSSHd\\\\FreeSSHDService.exe      |
| 22            | Terminate svcnet.exe, FreeSSHDService.exe, and plink.exe                                                                                                                                     |

*Table 4. ROMCOM 2.0 supported commands.*

## Protections and Mitigations

We recommend leveraging the indicators of compromise (IoCs) below to identify any impacts to your organization.

Palo Alto Networks detects and prevents Cuba Ransomware and Tropical Scorpius activity in the following ways:

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr) with
  * Detection for all indicators for Cuba Ransomware and related activity.
  * Anti-Ransomware module to detect Cuba Ransomware encryption behaviors on Windows systems.
  * Local Analysis detection for Cuba Ransomware and ROMCOM RAT binaries on Windows environments.
  * Behavioral Threat Protection rule prevents execution of related indicators.
* [WildFire](https://www.paloaltonetworks.com/products/secure-the-network/wildfire): All known samples are identified as malware.
* [Threat Prevention](https://www.paloaltonetworks.com/products/secure-the-network/subscriptions/threat-prevention) provides protection against Tropical Scorpius infrastructure.
* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering) and [DNS Security](https://www.paloaltonetworks.com/network-security/dns-security) identify domains associated with this group as malicious.

Indicators of compromise and associated TTPs can be found in the Tropical Scorpius [ATOM](https://unit42.paloaltonetworks.com/atoms/tropicalscorpius/).

If you think you may have been impacted or have an urgent matter, get in touch with the[Unit 42 Incident Response team](https://start.paloaltonetworks.com/contact-unit42.html) or call:

* North America Toll-Free: 866.486.4842 (866.4.UNIT42)
* EMEA: +31.20.299.3130
* APAC: +65.6983.8730
* Japan: +81.50.1790.0200

If you have cyber insurance, you can request Unit 42 by name. You can also take preventative steps by requesting any of our [cyber risk management services](https://www.paloaltonetworks.com/unit42/assess).

## Conclusion

Tropical Scorpius remains an active threat. The group's activity makes it clear that an approach to tradecraft using a hybrid of more nuanced tools focusing on low-level Windows internals for defense evasion and local privilege escalation can be highly effective during an intrusion.

Coupled with a splash of well-adopted and successful crimeware techniques, this presents unique challenges to defenders.

Unit 42 recommends that defenders have advanced logging capabilities deployed and configured properly such as Sysmon, Windows Command Line logging and PowerShell logging -- ideally forwarding to a Security Information and Event Management tool (SIEM) to create queries and detection opportunities. Keep computer systems patched and up to date wherever possible to reduce attack surface related to exploitation techniques.

Deploy an XDR/EDR solution to perform in-memory inspection and detect process injection techniques. Perform threat hunting looking for signs of unusual behavior related to security product defense evasion, service accounts for lateral movement and domain administrator-related user behavior.

## Indicators of Compromise

Driver Dropper:

07905de4b4be02665e280a56678c7de67652aee318487a44055700396d37ecd0  
af6561ad848aa1ba53c62a323de230b18cfd30d8795d4af36bf1ce6c28e3fd4e  
24e018c8614c70c940c3b5fa8783cb2f67cb13f08112430a4d10013e0a324eaa

ZeroLogon Hacktool:

ab5a3bbad1c4298bc287d0ac8c27790d68608393822da2365556ba99d52c5dfb  
6866e82d0f6f6d8cf5a43d02ad523f377bb0b374d644d2f536ec7ec18fdaf576  
3febf726ffb4f4a4186571d05359d2851e52d5612c5818b2b167160d367f722c  
3a8b7c1fe9bd9451c0a51e4122605efc98e7e4e13ed117139a13e4749e211ed0  
36bc32becf287402bf0e9c918de22d886a74c501a33aa08dcb9be2f222fa6e24  
1450f7c85bfec4f5ba97bcec4249ae234158a0bf9a63310e3801a00d30d9abcc

Cuba Ransomware:

0a3517d8d382a0a45334009f71e48114d395a22483b01f171f2c3d4a9cfdbfbf  
0eff3e8fd31f553c45ab82cc5d88d0105626d0597afa5897e78ee5a7e34f71b3

Privilege Escalation Tool:

a4665231bad14a2ac9f2e20a6385e1477c299d97768048cb3e9df6b45ae54eb8

KerberCache Hacktool:

cfe7b462a8224b2fbf2b246f05973662bdabc2c4e8f4728c9a1b977fac010c15

ROMCOM RAT:

B5978cf7d0c275d09bedf09f07667e139ad7fed8f9e47742e08c914c5cf44a53  
324ccd4bf70a66cc14b1c3746162b908a688b2b124ad9db029e5bd42197cfe99

Infrastructure:

CombinedResidency\[.\]org  
optasko\[.\]com

## Additional Resources

[From Zero to Domain Admin](https://thedfirreport.com/2021/11/01/from-zero-to-domain-admin/)  
[Qbot and Zerologon Lead to Full Domain Compromise](https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/)  
[CVE-2022-24521: Windows Common Log File System (CLFS) Logical-Error Vulnerability](https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2022/CVE-2022-24521.html)  
[Industrial Spy data extortion market gets into the ransomware game](https://www.bleepingcomputer.com/news/security/industrial-spy-data-extortion-market-gets-into-the-ransomware-game/)  
[(Ex)Change of Pace: UNC2596 Observed Leveraging Vulnerabilities to Deploy Cuba Ransomware](https://www.mandiant.com/resources/unc2596-cuba-ransomware)

*Updated Aug. 10, 2022, at 9:30 a.m. PT.
Updated Nov. 8, 2022, at 8 a.m. PT to remove a ROMCOM RAT IoC that was included in error.*
Back to top

### Tags

* [Cuba Ransomware](https://unit42.paloaltonetworks.com/tag/cuba-ransomware/ "Cuba Ransomware")
* [Investigation and Response](https://unit42.paloaltonetworks.com/tag/investigation-and-response/ "Investigation and Response")
* [ROMCOM RAT](https://unit42.paloaltonetworks.com/tag/romcom-rat/ "ROMCOM RAT")
* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")
* [Tropical Scorpius](https://unit42.paloaltonetworks.com/tag/tropical-scorpius/ "Tropical Scorpius")
* [UNC2596](https://unit42.paloaltonetworks.com/tag/unc2596/ "UNC2596")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware](https://unit42.paloaltonetworks.com/bumblebee-malware-projector-libra/ "Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware")

### Table of Contents

* 

### Related Articles

* [Know Ourselves Before Knowing Our Enemies: Threat Intelligence at the Expense of Asset Management](https://unit42.paloaltonetworks.com/asset-management/ "article - table of contents")
* [Why Threat Intelligence: A Conversation With Unit 42 Interns](https://unit42.paloaltonetworks.com/threat-intelligence-interns/ "article - table of contents")
* [Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "article - table of contents")

## Related Ransomware Resources

![Pictorial representation of Iran cyber attacks. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Security-Technology_Category_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) April 17, 2026 [#### Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/)

* [APK](https://unit42.paloaltonetworks.com/tag/apk/ "APK")

* [DDoS attacks](https://unit42.paloaltonetworks.com/tag/ddos-attacks/ "DDoS attacks")

* [GenAI](https://unit42.paloaltonetworks.com/tag/genai/ "GenAI")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iranian-cyberattacks-2026/ "Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)")  
  ![Pictorial representation of RaaS RansomHouse. Digital representation of cybersecurity concept with a padlock superimposed over computer circuit boards, symbolizing data protection and encryption technologies.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/06_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 17, 2025 [#### From Linear to Complex: An Upgrade in RansomHouse Encryption](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/)

* [ESXi](https://unit42.paloaltonetworks.com/tag/esxi/ "ESXi")

* [Jolly Scorpius](https://unit42.paloaltonetworks.com/tag/jolly-scorpius/ "Jolly Scorpius")

* [RansomHouse](https://unit42.paloaltonetworks.com/tag/ransomhouse/ "RansomHouse")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ransomhouse-encryption-upgrade/ "From Linear to Complex: An Upgrade in RansomHouse Encryption")  
  ![Pictorial representation of 01flip ransomware written in Rust. Digital artwork of a pixelated U.S. dollar bill disintegrating into small blocks against a blue data matrix background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/12/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) December 10, 2025 [#### 01flip: Multi-Platform Ransomware Written in Rust](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/)

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [CL-CRI-103](https://unit42.paloaltonetworks.com/tag/cl-cri-103/ "CL-CRI-103")

* [Cryptocurrency](https://unit42.paloaltonetworks.com/tag/cryptocurrency/ "Cryptocurrency")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/new-ransomware-01flip-written-in-rust/ "01flip: Multi-Platform Ransomware Written in Rust")  
  ![Pictorial representation of malicious LLMs. Close-up view of a digital wall displaying various glowing icons, representing a high-tech network interface.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/AdobeStock_1270203474-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) November 25, 2025 [#### The Dual-Use Dilemma of AI: Malicious LLMs](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/)

* [Credential Harvesting](https://unit42.paloaltonetworks.com/tag/credential-harvesting/ "Credential Harvesting")

* [Data exfiltration](https://unit42.paloaltonetworks.com/tag/data-exfiltration/ "data exfiltration")

* [LLM](https://unit42.paloaltonetworks.com/tag/llm/ "LLM")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/dilemma-of-ai-malicious-llms/ "The Dual-Use Dilemma of AI: Malicious LLMs")  
  ![Constellation image representing the constellation schema used by Palo Alto Networks Unit 42 to track nation-state and cybercrime threat actor groups](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/Generic-B-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) August 1, 2025 [#### Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/)

* [Academic Serpens](https://unit42.paloaltonetworks.com/tag/academic-serpens/ "Academic Serpens")

* [Agent Serpens](https://unit42.paloaltonetworks.com/tag/agent-serpens/ "Agent Serpens")

* [Agonizing Serpens](https://unit42.paloaltonetworks.com/tag/agonizing-serpens/ "Agonizing Serpens")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-actor-groups-tracked-by-palo-alto-networks-unit-42/ "Threat Actor Groups Tracked by Palo Alto Networks Unit 42 (Updated Aug. 1, 2025)")  
  ![Pictorial representation of Unit 42 threat attribution system. Illustration featuring a white triangle centered within an abstract cosmic background of purple and blue swirls and stars.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/07/Generic-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) July 31, 2025 [#### Introducing Unit 42's Attribution Framework](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/)

* [Advanced Persistent Threat](https://unit42.paloaltonetworks.com/tag/advanced-persistent-threat/ "Advanced Persistent Threat")

* [Bookworm](https://unit42.paloaltonetworks.com/tag/bookworm/ "Bookworm")

* [Nomenclature](https://unit42.paloaltonetworks.com/tag/nomenclature/ "nomenclature")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/unit-42-attribution-framework/ "Introducing Unit 42’s Attribution Framework")  
  ![Pictorial representation of the ransomware landscape. Digital artwork of a disintegrating U.S. dollar bill with pixelated effects on a cyber-inspired background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/04/05_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-report-white-1.svg)Trend Reports](https://unit42.paloaltonetworks.com/category/trend-reports/) April 23, 2025 [#### Extortion and Ransomware Trends January-March 2025](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/)

* [BianLian](https://unit42.paloaltonetworks.com/tag/bianlian/ "BianLian")

* [Akira ransomware](https://unit42.paloaltonetworks.com/tag/akira-ransomware/ "Akira ransomware")

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/2025-ransomware-extortion-trends/ "Extortion and Ransomware Trends January-March 2025")  
  ![A pictorial representation of Akira ransomware, distributed by Howling Scorpius. A person's hand typing on a keyboard with a digital screen displaying the word "password" highlighted in blue, set against a backdrop of various cybersecurity interface graphics.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/09_Cybercrime_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) December 2, 2024 [#### Threat Assessment: Howling Scorpius (Akira Ransomware)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/)

* [Howling Scorpius](https://unit42.paloaltonetworks.com/tag/howling-scorpius/ "Howling Scorpius")

* [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/ "Leak site")

* [Torrenting](https://unit42.paloaltonetworks.com/tag/torrenting/ "torrenting")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-howling-scorpius-akira-ransomware/ "Threat Assessment: Howling Scorpius (Akira Ransomware)")  
  ![Pictorial representation of a threat like BlackSuit ransomware. An illustration of a modern workspace with a laptop displaying cybersecurity icons, surrounded by stacks of coins and a credit card, all depicted in a neon, digital art style.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/11/04_Ransomware_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) November 20, 2024 [#### Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/)

* [BlackSuit ransomware](https://unit42.paloaltonetworks.com/tag/blacksuit-ransomware/ "BlackSuit ransomware")

* [Construction](https://unit42.paloaltonetworks.com/tag/construction/ "construction")

* [Education](https://unit42.paloaltonetworks.com/tag/education/ "Education")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/threat-assessment-blacksuit-ransomware-ignoble-scorpius/ "Threat Assessment: Ignoble Scorpius, Distributors of BlackSuit Ransomware")  
  ![A representation of a threat group like Jumpy Pisces. Illustrative image featuring two fish and the Pisces constellation superimposed on a stylized, abstract background with flowing purple waves and a starry night sky.](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/10/Pisces-NK-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/threat-actor-groups.svg)Threat Actor Groups](https://unit42.paloaltonetworks.com/category/threat-actor-groups/) October 30, 2024 [#### Jumpy Pisces Engages in Play Ransomware](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/)

* [North Korea](https://unit42.paloaltonetworks.com/tag/north-korea/ "North Korea")

* [Jumpy Pisces](https://unit42.paloaltonetworks.com/tag/jumpy-pisces/ "Jumpy Pisces")

* [Fiddling Scorpius](https://unit42.paloaltonetworks.com/tag/fiddling-scorpius/ "Fiddling Scorpius")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/north-korean-threat-group-play-ransomware/ "Jumpy Pisces Engages in Play Ransomware")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
