Home/Threat Actor/Termite Ransomware
Threat Actor

Termite Ransomware

termite_ransomware · unknown_likely_russia_aligned · active since 2024-11

Termite Ransomware (Cyfirma canonical naming, November 2024 emergence) is a financially-motivated cybercriminal ransomware operation derived from the Babuk ransomware family source code lineage (Babuk source code leaked publicly September 2021)

achieved significant public visibility through the November 21, 2024 ransomware attack on Blue Yonder supply chain management software vendor whose customers include Starbucks, Morrisons, Sainsbury's, Procter & Gamble, the attack cascaded operational disruption across many downstream customers (Starbucks employee scheduling and payroll disruption, Morrisons warehouse and inventory disruption, Sainsbury's operational impact, Fortune 500 manufacturer supply-chain disruption)

operational case study in supply- chain ransomware attacks against consolidated-services vendors, operationally similar in significance to Brain Cipher PDN Indonesia attack (brain_cipher.yaml)

Babuk source code lineage positioning operationally distinguishes cluster from ALPHV-derivative successors (Cicada3301), INC Ransom-derivative successors (Lynx), LockBit Black builder derivatives (DragonForce, Brain Cipher), and Conti successors (Black Basta, Royal/BlackSuit), all curated separately in this corpus.

standard double-extortion operational model with VMware ESXi hypervisor targeting variant.

unknown_likely_russia_aligned confidence: high 8 aliases

Profile

Termite Ransomware (Cyfirma canonical naming, November 2024 emergence) is a financially-motivated cybercriminal ransomware operation that emerged in approximately November 2024 with operational tooling derived from the Babuk ransomware family source code lineage. The cluster achieved significant public visibility through the November 21, 2024 ransomware attack on Blue Yonder, a major US-based supply chain management software vendor whose customers include Starbucks, Morrisons, Sainsbury's, Procter & Gamble, and numerous Fortune 500 retailers and manufacturers. The cluster's operational distinctiveness is concentrated in two dimensions: (1) SUPPLY CHAIN RANSOMWARE TARGETING CASE STUDY. The Blue Yonder November 2024 attack represented a documented case study in supply-chain ransomware attacks where compromise of a single vendor cascades operational disruption across many downstream customers. Starbucks experienced operational disruption affecting employee scheduling and payroll for an extended period.

Morrisons experienced supply chain disruption affecting warehouse and inventory operations; Sainsbury's and additional UK retail customers experienced operational impact.

multiple Fortune 500 manufacturers experienced supply chain management infrastructure disruption. The attack illustrates the operational leverage available to ransomware operators who successfully compromise consolidated supply-chain or shared-services vendors, operationally similar in case-study significance to the Brain Cipher PDN Indonesia attack (brain_cipher.yaml) and the broader ransomware ecosystem trend toward consolidated- services targeting. (2) BABUK SOURCE CODE LINEAGE OPERATIONAL POSITIONING. Termite operates within the Babuk-derivative ransomware sub-ecosystem, Babuk source code was leaked publicly in September 2021 and has enabled multiple successor operations including Rook, Pandora, Nokoyawa, Cylance, numerous ESXi- targeting variants, and Termite. The Babuk-derivative ecosystem represents one of the longest-documented multi- cluster code-genealogy ransomware patterns. Termite's positioning within the Babuk-derivative sub-ecosystem operationally distinguishes the cluster from other code- genealogy lineages curated in this corpus: ALPHV / BlackCat- derivative successors (Cicada3301), INC Ransom source-code- derivative successors (Lynx), LockBit Black builder derivatives (DragonForce, Brain Cipher), and Conti collapse successors (Black Basta, Royal/BlackSuit). Operational tradecraft includes initial access via compromised credentials and selective N-day vulnerability exploitation, conventional lateral movement, data exfiltration via rclone to cloud storage, Babuk-derived ransomware encryption with VMware ESXi hypervisor targeting variant, and double- extortion pressure via leak-site data publication. Termite is curated alongside the broader ransomware ecosystem coverage in this corpus. Its operational distinctiveness within this ecosystem is the Blue Yonder supply-chain attack case study and the Babuk source code lineage positioning.

Aliases

8
termite_ransomwaretermite ransomwaretermitetermite ransomware operatorsbabuk_source_code_lineage_termitebabuk_derivative_termiteblue yonder attackers november 2024termiteransomware

Notable Campaigns

2
2024Blue Yonder Supply Chain Management Vendor Attack (November 21, 2024)
2024Babuk Source Code Lineage Derivation and Sub-Ecosystem Positioning

Attribution & Reporting

Attributed by
CyfirmaSOCRadarSymantec / Broadcom Threat Hunter TeamHalcyonRecorded FutureSentinelOneTrend MicroSophosBleepingComputerCISA (US Cybersecurity and Infrastructure Security Agency)FBI (Federal Bureau of Investigation)UK National Cyber Security Centre (NCSC)Bridewell Consulting
Key reporting
reportCyfirma: Termite Ransomware Blue Yonder Attack Analysis (November 2024)
reportSOCRadar: Termite Ransomware Dark Web Profile
reportSymantec / Broadcom Threat Hunter Team: Termite Ransomware Technical Analysis
reportHalcyon: Termite Ransomware Threat Intelligence Profile
reportBridewell Consulting: Termite Ransomware Blue Yonder Supply Chain Attack Analysis
reportMalpedia Actor / Malware Profile: Termite Ransomware

Operational

State sponsor

Cybercriminal ransomware operation that emerged in approximately November 2024 with operational tooling derived from the Babuk ransomware family source code (Babuk source code had been leaked publicly in September 2021, providing foundational tooling for multiple subsequent ransomware operations including Rook, Pandora, Nokoyawa, Cylance, ESXi- targeting variants, and now Termite). Industry analysis (Cyfirma, SOCRadar, Broadcom Symantec Threat Hunter Team, Halcyon) documented substantial code overlap between Termite ransomware binaries and the Babuk source code lineage, consistent with operational positioning within the Babuk- derivative ransomware sub-ecosystem. The cluster's operational origin is unclear in the public record: industry analysis has not formally attributed Termite to specific national origin, government affiliation, or established cybercriminal organization.

Operational tradecraft, ransom negotiation patterns, victim country avoidance consistent with Russian-aligned cybercriminal ecosystem norms, and operational tempo are consistent with the broader Russian-aligned cybercriminal ransomware ecosystem. The cluster's operational profile achieved significant public visibility through the November 2024 ransomware attack on Blue Yonder, a major US-based supply chain management software vendor whose customers include Starbucks, Morrisons supermarket chain (UK), Sainsbury's, Procter & Gamble, and numerous other Fortune 500 retailers and manufacturers. The Blue Yonder attack resulted in significant operational disruption for Blue Yonder customers including Starbucks (which experienced operational disruption affecting employee scheduling and payroll for an extended period), Morrisons, and adjacent organizations dependent on Blue Yonder supply-chain management infrastructure.

The operational impact represented a documented case study in supply-chain ransomware attacks where compromise of a single vendor cascades operational disruption across many downstream customers.

Motivations
financial_gain, ransomware_extortion, double_extortion_data_exfiltration_and_encryption, supply_chain_ransomware_targeting, high_leverage_supply_chain_vendor_compromise, ransom_payment_extraction
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)33/60 · 55%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped

CVEs Exploited

1
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin