← All actors

Termite

Aliases: Termite ransomware

Source profile review date: 2026-06-21

Added to the source registry: 2024-11-17 · Source snapshot: 2026-09-15

Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.

Research status: Existing researched dossier

This dossier separates actor-specific source information from general defensive analysis. Recommendations and investigation questions are not additional claims about the actor. Public evidence remains limited where explicitly stated.

Locally generated translation; linguistic review is still pending.

Executive summary

Termite is a ransomware group that became visible at the end of 2024/2025 and is linked to Babuk-like code, supply-chain impact and large data exfil claims.

Termite is relevant due to claims about Blue Yonder, sensitive data from other victims and the use of a Babuk-like code base. The profile focuses on supply chain risk, data stealing and recovery.

Latest five known victim claims

Loading stored claims…

    These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.

    Management summary

    Termite is important to organizations because the group shows how ransomware impact can work through vendors and platforms. An attack on a service provider or supply chain party may affect processes with many customers, even when those customers themselves are not directly compromised.

    Public reporting links Termite to end 2024/2025 activity, Babuk-like code and large data exfil claims. That makes the group technically and organizationally relevant: defenders need to understand both payload behaviour and chain dependence.

    The practical question is whether critical service providers, platform accounts, service accounts, data exchange and recovery processes are sufficiently separate and monitored. Termite not only affects servers; the real impact is in business processes and confidence in chains.

    Grouping and development

    Termite became publicly visible as ransomware and extortion group with leak-site activity. Analyses describe a relationship to or use custom Babuk code. Babuk code is more frequently reused in the ransomware ecosystem, which can cause technical overlap without the same operator behind each attack.

    The claim around Blue Yonder attracted attention because disruption with a supply chain software provider may have downstream effect. Such cases show that ransomware groups see value in platforms that support many customers or logistics processes.

    Termite should therefore be followed as more than one payload name. The group is relevant to organisations that depend on software providers, managed services, logistics platforms or data-rich service providers.

    Operation and attack chain

    The attack chain seems to fit modern double expansion: access, internal exploration, privilege collection, data identification, exfiltrating and then applying encryption or publication pressure. In supply chain parties, the actor searches for data or systems with wide operational impact.

    The Babuk-like code base is relevant for encryption logic detection and Linux/ESXi-like scenario scripts, but should not be the only focus point. The actor can use common tools and valid accounts to access and exfil.

    For organisations with virtualization, logistics platforms or high customer data research should explicitly look at management interfaces, service accounts, API- links, database exports, backup repository and hypervisor management. If those layers are hit, recovery is more complex than just restoring endpoints.

    Termite-cases require chain research: which customers, processes or integrations depend on the affected platform? Which third party data was in the environment? What access did the actor have to customer environments or only internal servers?

    Known IOCs and artifacts

    Public artifacts are leak-site claims, Babuk-like payload features, ransom notes, exfiltration claims and sector claims around supply-chain and sensitive data. Hard hashes must be retrieved from current sources or own telemetry.

    Behaviour indicators include large data transfers, customer data staging, access to platform databases, service account abuse, server layer encryption, access to virtualization management and critical application disruption.

    Use Babuk-related detections carefully. Reuse of code means that signatures may be useful, but don't automatically prove attribution. Combine payload features with network, identity and data access tracks.

    Victim pattern and lessons

    Blue Yonder is mentioned in the public domain in Termite context and illustrates supply-chain impact. Other reports mention sensitive data among victims such as Genea. The lesson is that data extortion and platform disruption reinforce each other.

    For service providers, the question is which customer data and operational processes are in the same trust zone. Ransomware groups search for places where a single intrusion is putting a lot of pressure on them.

    Supplier monitoring is important for service providers' customers. Contracts should make logging, reporting deadlines, data segregation, recovery tests and responsibility for ransomware concrete.

    How to arm yourself

    Segment supply chain platforms and limit service accounts. API- links must have minimum permissions, tokens must be rotatable and database exports must be logged.

    Monitor virtualization, backup and platform management. Access to ESXi, Hyper-V, Nutanix, storage management and backup software must be logged separately and not run via regular domain admins.

    Practice a supplier incident. Pre-determine how to search for scope: was customer data affected, customer environments accessible, which logs are secured and when is recovery reliable?

    Identity, naming and attribution

    For Termite, the operational starting point is an exact identity match. The local dossier records the following names or aliases: Termite ransomware. An alias is a search aid, not independent evidence of shared operators. Similar names, reused logos and the same extortion vocabulary cannot establish a relationship between groups. Analysts should retain the original spelling of a claim and distinguish the publisher, malware family and suspected intrusion operator. Those roles can belong to different people. This prevents an incident being assigned to the wrong group simply because a filename or public post resembles an earlier case. Any proposed relationship needs its own dated, attributable source.

    Timeline and interpretation of dates

    The source registry date available for Termite is 2024-11-17; the metadata snapshot was collected on 2026-09-15. These timestamps describe the available record, not a proven beginning of criminal operations. Registration may follow earlier activity, and a claim can concern an older incident. A defensible timeline separates suspected intrusion, data access, discovery by the victim, publication by the claimant and discovery by the monitoring service. The profile review date is another independent timestamp. Analysts should not silently convert one date into another. When sources disagree, preserve both observations and their provenance, then explain the uncertainty rather than presenting a falsely precise attack chronology.

    Indicators of compromise (IOCs)

    Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.

    TypeValueSourceContext
    relationshipmodified Babuk ransomware coderansomware.live / Splunk reportingBasic code relationship; use fees with caution.
    caseBlue Yonder supply-chain impact claimpublic Termite reportingImportant chain risk scenario.
    behaviorlarge data exfiltration and leak-site pressurepublic reportingDouble-extortion behavior.

    Sources

    Evidence and limitations

    Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.