Tropical Scorpius, RomCom

Description

(Palo Alto) The most recent Unit 42 Ransomware Threat Report includes observations of Cuba Ransomware impacting 33 organizations. As of July 2022, Tropical Scorpius has used Cuba Ransomware to impact 27 additional organizations across multiple vectors, such as Professional and Legal Services, State and Local Government, Manufacturing, Transportation and Logistics, Wholesale and Retail, Real Estate, Financial Services, Health Care, High Technology, Utilities and Energy, Construction, and Education. A total of 60 organizations were exposed by this ransomware gang on its leak site since the group first surfaced in 2019.

Names

NameName-Giver
Tropical ScorpiusPalo Alto
RomComPalo Alto
Void RabisuTrend Micro
DEV-0978Microsoft
Storm-0671Microsoft
Storm-0978Microsoft
UNC2596Mandiant
CIGARMandiant
UAC-0180CERT-UA

Country

Motivation

  • Information theft and espionage
  • Financial gain

First Seen

2019

Observed Sectors

Tools

Operations

Information

Other Information

Uuid

8e23fbaa-47d5-4fce-8b85-9fbb9aeecd87

Last Card Change

2025-06-28