Today > 13 Critical | 36 High | 32 Medium vulnerabilities   -   You can now download lists of IOCs here!

A Technical Look At The New 'Termite' Ransomware That Hit Blue Yonder

Dec. 9, 2024, 11:31 a.m.

Description

The Termite ransomware, a rebranded version of Babuk, recently targeted supply chain management platform Blue Yonder. This new strain employs advanced tactics, including double extortion, to maximize its impact. Upon execution, it terminates services, deletes shadow copies, empties the recycle bin, and encrypts files while avoiding certain system folders. The ransomware spreads through network shares and appends a '.termite' extension to encrypted files. It uses multiple MITRE ATT&CK techniques for execution, defense evasion, discovery, and impact. The emergence of Termite highlights the need for robust cybersecurity measures, proactive threat intelligence, and effective incident response strategies to counter evolving ransomware threats.

Date

Published: Dec. 7, 2024, 12:25 p.m.

Created: Dec. 7, 2024, 12:25 p.m.

Modified: Dec. 9, 2024, 11:31 a.m.

Attack Patterns

Vasa Locker

Babyk

Babuk - S0638

Termite

Termite

T1135

T1490

T1070.004

T1204.002

T1486

T1082

T1105

T1083

T1140

Additional Informations

Technology