Termite is a financially motivated ransomware and extortion operation, also referred to as the Termite ransomware group or Termite ransomware operators. It maintains a dedicated data leak site to publicize victim claims and pressure organizations through threatened or claimed disclosure of stolen information. Its claimed targets span healthcare, manufacturing, industrial equipment distribution, transportation, financial services, real estate, education, software services, and media, with a substantial concentration in the United States. Termite's extortion activity includes claims of stealing sensitive medical records, personal information, financial and tax records, employment information, and other corporate documents. Claimed victims include Affinia Healthcare, Indiana Mills and Manufacturing, Wiese USA, theLender, TruAmerica Multifamily, UEI College, and News-Press & Gazette Company. The operation has used short contact deadlines to pressure victims. Public victim listings and data-theft allegations do not independently establish the scope of a compromise or confirm that Termite was the sole intruder. Its country of origin, organizational structure, initial-access methods, and detailed malware capabilities are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
An unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory in Cleo Harmony, VLTrader, and LexiCom before version 5.8.0.24.
A December 13 reply states: “a new CVE was cut for the exploit we saw earlier” and links to a CVE record with the identifier CVE-2024-12632.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Reportedly conducted a ransomware attack against iDentalSoft, a Brazil-based provider of cloud-based dental practice management software. The breach reportedly occurred on October 9, 2026, at 12:22 UTC and was discovered at 12:59 UTC. The content provides no technical details or independent attribution evidence.
Termite lists iDentalSoft, a cloud-based dental practice management software provider identified in the post as located in Brazil, as a victim discovered on October 9, 2026. The listing provides no stolen-data details, proof of compromise, ransom demand, or deadline.
The report attributes a ransomware attack against Aon, an international professional services firm, to Termite. It lists the breach date as October 6, 2026, and discovery as October 7, 2026, but provides no technical evidence or operational details.
Termite lists Aon plc, an international insurance brokerage and professional services firm, as a victim; the recorded discovery date is October 7, 2026. The post provides no stolen-data details, proof of compromise, ransom amount, or deadline.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.