Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors termite

Description

Termite is a ransomware group first identified in late 2024 using a modified version of Babuk ransomware code; its most notable attack was the November 2024 breach of supply-chain software firm Blue Yonder, claiming 680 GB of exfiltrated data and disrupting major customers including Starbucks. Known victims: 40 1 ransom note(s) on file

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 1 week ago

Executive Summary

Termite is a ransomware group identified as a threat actor targeting various sectors through malicious activities. Originating from a modified version of the Babuk ransomware, Termite has demonstrated significant operational capability since its first appearance in May 2023. Their primary motivation revolves around financial gain through the deployment of ransomware and disruption of businesses.

Goals & Targeting

Termite targets a broad range of industries, including software providers, retail, healthcare, education, and manufacturing, among others. Their choice of victims suggests a focus on organizations that are critical to supply chains or have significant financial exposure. The primary motivation for Termite is financial gain through ransom payments, with a secondary objective of disrupting operations to coerce timely payouts.

Enhanced Description

Termite is a sophisticated cybercriminal group primarily operating within the ransomware landscape. The group gained notoriety after attacking Blue Yonder, a supply-chain software firm, in November 2023, resulting in the exfiltration of 680 GB of data and significant disruptions to major customers including Starbucks. Termite's operations typically involve targeted attacks leveraging their capabilities and tools to compromise systems, deploy ransomware, and demand payments for decryption keys. The group is known for its calculated approach and ability to target high-value sectors with substantial financial implications.

Key Capabilities

  • Spear-phishing campaigns
  • Ransomware deployment (modified Babuk variant)
  • Data exfiltration
  • Credential compromise and lateral movement within networks

MITRE ATT&CK Tactics

Data Destruction
Credential Access
Discovery
Lateral Movement
Exfiltration

ATT&CK Techniques

T1566.001
T1078
T1091
T1483.001
T1049
T1270

Software / Tooling

Babuk Ransomware (modified)
Custom tools for lateral movement and credential dumping

Campaigns & Victims

Termite has been active since May 2023, with a notable spike in campaign activity starting in late 2024. The group primarily targets North American and European organizations, leveraging supply chain attacks to maximize impact. Their campaigns often involve compromising third-party vendors to infiltrate primary targets, as seen in the Blue Yonder attack. Notable operations include attacks on Millennium Dental Technologies, City of Huntington, and multiple manufacturing and retail firms.

IOC Patterns

  • Spear-phishing emails with malicious attachments
  • Use of MD5 hashes for payload signatures
  • Command-and-control (C2) communication over specific IP addresses
  • Lateral movement using compromised credentials

Recommended Actions

  • Implement multi-factor authentication (MFA) for critical accounts
  • Monitor network traffic for known Termite C2 IPs: 193.43.104.153, 87.121.45.33
  • Conduct regular backups and store them offline or in secure cloud storage
  • Educate employees on spear-phishing tactics and suspicious emails
  • Enhance endpoint detection and response (EDR) capabilities

Suggested Tags

ransomware
financial-gain
supply-chain
retail
healthcare

Confidence Assessment

The information available on Termite is moderately reliable, given the group's visibility in high-profile attacks and associated IOCs. However, gaps remain regarding their exact TTPs beyond known campaigns and whether they maintain affiliations with other ransomware groups.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

12

Campaigns

4

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
ransomware
financial-gain
supply-chain
retail
healthcare

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
May 11, 2023
Last Seen
Jul 28, 2026
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.