Termite Ransomware, identified in late 2024, has emerged as a significant cyber threat, leveraging advanced tactics and targeting specific vulnerabilities. Its operations include data theft, extortion, and encryption, with notable attacks such as the breach of Blue Yonder. The group is suspected to have links to Babuk and Cl0p, indicating a complex ransomware landscape. Affected: Termite Ransomware, Babuk, Cl0p
Keypoints :
- Termite Ransomware specializes in data theft, extortion, and encryption.
- First identified in late 2024, it is linked to multiple high-profile cyberattacks.
- The group uses a modified version of Babuk ransomware.
- Termite targets specific system vulnerabilities for its attacks.
- Notable attack on Blue Yonder disrupted operations across multiple companies.
- Termite employs double extortion tactics, threatening to leak stolen data.
- The group has connections to other ransomware actors, indicating a collaborative threat environment.
- Organizations need proactive measures to defend against such sophisticated threats.
MITRE Techniques :
- Execution (T1204.002) โ User Execution: Termite relies on user interactions to execute its ransomware.
- Defense Evasion (T1070.004) โ Indicator Removal on Host: The ransomware removes indicators of compromise to evade detection.
- Discovery (T1083) โ File and Directory Discovery: It scans for files and directories to identify targets for encryption.
- Lateral Movement (T1021) โ Remote Services: Termite uses remote services to spread across networks.
- Privilege Escalation (T1078) โ Valid Accounts: The group exploits valid accounts to gain higher privileges.
- Discovery (T1135) โ Network Share Discovery: It discovers network shares to encrypt files on shared drives.
- Command and Control (T1105) โ Ingress Tool Transfer: The ransomware transfers tools to maintain control over the infected systems.
- Impact (T1486) โ Data Encrypted for Impact: Termite encrypts data to maximize the impact on victims.
- Impact (T1490) โ Inhibit System Recovery: The ransomware disables recovery options to prevent data restoration.
Indicator of Compromise :
- [domain] termite-ransomware-leak-site.onion
- [url] http://blue-yonder-attack.com
- [url] http://cleosoftware-vulnerabilities.com
- [others ioc] 680GB of sensitive data exfiltrated
- Check the article for all found IoCs.
Full Research: https://socradar.io/dark-web-profile-termite-ransomware/