A Technical Look At The New 'Termite' Ransomware That Hit Blue Yonder
Dec. 9, 2024, 11:31 a.m.
Description
The Termite ransomware, a rebranded version of Babuk, recently targeted supply chain management platform Blue Yonder. This new strain employs advanced tactics, including double extortion, to maximize its impact. Upon execution, it terminates services, deletes shadow copies, empties the recycle bin, and encrypts files while avoiding certain system folders. The ransomware spreads through network shares and appends a '.termite' extension to encrypted files. It uses multiple MITRE ATT&CK techniques for execution, defense evasion, discovery, and impact. The emergence of Termite highlights the need for robust cybersecurity measures, proactive threat intelligence, and effective incident response strategies to counter evolving ransomware threats.
Tags
Date
- Created: Dec. 7, 2024, 12:25 p.m.
- Published: Dec. 7, 2024, 12:25 p.m.
- Modified: Dec. 9, 2024, 11:31 a.m.
Attack Patterns
- Vasa Locker
- Babyk
- Babuk - S0638
- Termite
- Termite
- T1135
- T1490
- T1070.004
- T1204.002
- T1486
- T1082
- T1105
- T1083
- T1140
Additional Informations
- Technology