Termite is a ransomware group first identified in late 2024 using a modified version of Babuk ransomware code; its most notable attack was the November 2024 breach of supply-chain software firm Blue Yonder, claiming 680 GB of exfiltrated data and disrupting major customers including Starbucks. Known victims: 40 1 ransom note(s) on file
Objectives
Executive Summary
Termite is a ransomware group identified as a threat actor targeting various sectors through malicious activities. Originating from a modified version of the Babuk ransomware, Termite has demonstrated significant operational capability since its first appearance in May 2023. Their primary motivation revolves around financial gain through the deployment of ransomware and disruption of businesses.
Goals & Targeting
Termite targets a broad range of industries, including software providers, retail, healthcare, education, and manufacturing, among others. Their choice of victims suggests a focus on organizations that are critical to supply chains or have significant financial exposure. The primary motivation for Termite is financial gain through ransom payments, with a secondary objective of disrupting operations to coerce timely payouts.
Enhanced Description
Termite is a sophisticated cybercriminal group primarily operating within the ransomware landscape. The group gained notoriety after attacking Blue Yonder, a supply-chain software firm, in November 2023, resulting in the exfiltration of 680 GB of data and significant disruptions to major customers including Starbucks. Termite's operations typically involve targeted attacks leveraging their capabilities and tools to compromise systems, deploy ransomware, and demand payments for decryption keys. The group is known for its calculated approach and ability to target high-value sectors with substantial financial implications.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Termite has been active since May 2023, with a notable spike in campaign activity starting in late 2024. The group primarily targets North American and European organizations, leveraging supply chain attacks to maximize impact. Their campaigns often involve compromising third-party vendors to infiltrate primary targets, as seen in the Blue Yonder attack. Notable operations include attacks on Millennium Dental Technologies, City of Huntington, and multiple manufacturing and retail firms.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The information available on Termite is moderately reliable, given the group's visibility in high-profile attacks and associated IOCs. However, gaps remain regarding their exact TTPs beyond known campaigns and whether they maintain affiliations with other ransomware groups.
No techniques linked yet.
No tools linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
12
Campaigns
4
IOCs
0
Observed Data
0
Tactics