Termite is a ransomware and data-extortion operation, also referred to as Termite Ransomware Group, Termite Ransomware Operators, and Termite (Opendir). The group operates a dedicated leak site and has publicly named victims across multiple sectors, including healthcare, manufacturing and industrial services, financial services, real estate, and public-sector services. Its activity has prominently affected organizations in the United States and Australia. Termite has been associated with data theft and publication as part of extortion operations. In attacks against healthcare providers including Insight Hospital and Medical Center and Australian fertility-services provider Genea, the operation claimed substantial data theft and publicly released or was linked to the external publication of sensitive data. Reporting has also described Termite ransomware as encrypting victim files and directing victims to a dark-web site for ransom-payment communications. Termite was initially suspected of involvement in exploitation of Cleo managed file-transfer vulnerabilities, but the Clop ransomware operation subsequently claimed responsibility for that campaign; Termite attribution for the Cleo activity is therefore not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware/extortion group claiming seven compromises during the reporting week.
Conducted a ransomware attack against Crossett, a U.S.-based petroleum transportation company.
Conducted a ransomware attack against Sealcon, a U.S.-based cable-management and electrical/electronic components manufacturer.
Conducted a ransomware attack against TruAmerica Multifamily, a U.S. multifamily real-estate investment and asset-management firm.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.