TROPICAL SCORPIUS
Threat IntelligenceAPTJanuary 15, 202615 min read

UNC2596: Threat Intelligence Profile

Threat cluster operating Cuba ransomware with custom loaders and kernel driver exploits, targeting critical infrastructure and government organizations for double extortion.

Scroll

UNC2596 / Cuba Ransomware (also known as Tropical Scorpius) is a state-sponsored advanced persistent threat group attributed to Likely Russian-speaking, active since 2019. The group primarily targets critical infrastructure, financial, government sectors.

Overview & Attribution

Threat cluster operating Cuba ransomware with custom loaders and kernel driver exploits, targeting critical infrastructure and government organizations for double extortion.

Threat Assessment

UNC2596 has been active since 2019, attributed to Likely Russian-speaking. The group is known for targeting critical infrastructure, financial, government using a combination of custom malware, living-off-the-land techniques, and sophisticated social engineering.

Arsenal & Tools

UNC2596 employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

The group focuses on critical infrastructure, financial, government sectors, with operations spanning multiple geographic regions. Their campaigns typically involve carefully crafted spearphishing, strategic watering holes, and exploitation of public-facing applications.

Operational Pattern

UNC2596 is characterized by persistent, long-term access operations. Once inside a target network, the group establishes multiple redundant persistence mechanisms and moves laterally to high-value systems before beginning data exfiltration.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1190 Exploit Public-Facing AppProxyShell/ProxyLogon exploitation
ExecutionT1059.001 PowerShellPowerShell post-exploitation
Privilege EscalationT1068 Exploitation for Privilege EscalationBYOVD kernel exploits
Defense EvasionT1562.001 Disable Security ToolsBURNTCIGAR driver killer
ImpactT1486 Data Encrypted for ImpactCuba ransomware encryption
C2T1071.001 Web ProtocolsCobalt Strike Beacon C2

Notable Campaigns

UNC2596 has been linked to multiple significant campaigns targeting critical infrastructure, financial, government organizations. The group continuously evolves its tooling and infrastructure to evade detection while maintaining persistent access to compromised networks.

Detection & Defense

Defend Against UNC2596

Mjolnir Security provides specialized capabilities to detect and respond to UNC2596 operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for UNC2596 TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of UNC2596 campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: January 15, 2026