TERMITE is a password-protected, memory-only PowerShell dropper associated with UNC2596 (Cuba ransomware) intrusions. It uses obfuscated PowerShell to execute embedded encrypted shellcode in memory, then retrieves additional shellcode and encrypted payloads from command-and-control infrastructure. The subsequent shellcode decrypts and reflectively loads payloads without requiring their conventional installation on disk. TERMITE has been used to deploy BUGHATCH, Cobalt Strike Beacon, and a Metasploit stager during Cuba ransomware operations. UNC2596 commonly used TERMITE after obtaining access to vulnerable public-facing Microsoft Exchange servers and establishing a foothold with web shells or backdoors. The TERMITE name has also been applied to unrelated malware and ransomware activity; those uses should not be conflated with the Cuba-associated PowerShell dropper.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Finally, there’s a memory-only dropper that fetches the above payloads and loads them, called Termite.
Threat hunters disclosed multiple ClickFix campaigns, including one leading to a hands-on-keyboard attack that deployed the Termite ransomware.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware is a typical backdoor with the added functionality of being able to serve as a SOCKS proxy, which would allow it to intercept the contents of some kinds of web traffic.
The following analytic detects modifications to files with extensions commonly associated with ransomware... This activity is significant because it suggests an attacker is attempting to encrypt or alter files... If this is a true ransomware attack, there will be a large number of files created with these extensions.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware referenced as having impacted Blue Yonder, with downstream effects on Starbucks.
"Termite ransomware breaches linked to ClickFix CastleRAT attacks"
Ransomware deployed following ClickFix-driven social engineering and hands-on-keyboard intrusion activity.
Ransomware deployed following a ClickFix-driven intrusion culminating in hands-on-keyboard activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.