news.mlab.sh
Threat intelligence
Threat actor

Tropical Scorpius

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Russia
First seen
2019-01-01 00:00:00
Motivation
Information theft and espionage, Financial gain
Targeted sectors
Construction, Education, Energy, Financial, Government, Healthcare, High-Tech, Manufacturing, Shipping and Logistics, Transportation
TLP
WHITE

(Palo Alto) The most recent Unit 42 Ransomware Threat Report includes observations of Cuba Ransomware impacting 33 organizations. As of July 2022, Tropical Scorpius has used Cuba Ransomware to impact 27 additional organizations across multiple vectors, such as Professional and Legal Services, State and Local Government, Manufacturing, Transportation and Logistics, Wholesale and Retail, Real Estate, Financial Services, Health Care, High Technology, Utilities and Energy, Construction, and Education. A total of 60 organizations were exposed by this ransomware gang on its leak site since the group first surfaced in 2019.

Also known as

CIGARDEV-0978RomComStorm-0671Storm-0978TA829Tropical ScorpiusUAC-0180UNC2596Void Rabisu

Coverage 1