A Technical Look At The New 'Termite' Ransomware That Hit Blue Yonder
Dec. 9, 2024, 11:31 a.m.
Tags
External References
Description
The Termite ransomware, a rebranded version of Babuk, recently targeted supply chain management platform Blue Yonder. This new strain employs advanced tactics, including double extortion, to maximize its impact. Upon execution, it terminates services, deletes shadow copies, empties the recycle bin, and encrypts files while avoiding certain system folders. The ransomware spreads through network shares and appends a '.termite' extension to encrypted files. It uses multiple MITRE ATT&CK techniques for execution, defense evasion, discovery, and impact. The emergence of Termite highlights the need for robust cybersecurity measures, proactive threat intelligence, and effective incident response strategies to counter evolving ransomware threats.
Date
Published: Dec. 7, 2024, 12:25 p.m.
Created: Dec. 7, 2024, 12:25 p.m.
Modified: Dec. 9, 2024, 11:31 a.m.
Attack Patterns
Vasa Locker
Babyk
Babuk - S0638
Termite
Termite
T1135
T1490
T1070.004
T1204.002
T1486
T1082
T1105
T1083
T1140
Additional Informations
Technology