Termite is a ransomware and data-extortion operation active by at least 2025 and associated with intrusions across multiple countries and sectors. Publicly reported victims and claimed victims span healthcare, manufacturing, media, education, government-related services, and food-related organizations, with a strong concentration of U.S. targets and additional activity affecting Australia and other countries. The group operates a leak site and has been observed claiming large-scale data theft from victims, including publication of stolen data when extortion demands are not met. Reported incidents linked to Termite include attacks against healthcare providers such as Affinia Healthcare, Insight Hospital and Medical Center, MedHelp Clinics, and Genea, as well as organizations in manufacturing and industrial distribution, media, and education. Termite is characterized primarily as an extortion-focused ransomware actor. Reported tradecraft includes data exfiltration, operation of a leak site, and use of ransomware that encrypts victim files while directing victims to a hidden service for ransom negotiations. In multiple cases, the group claimed theft of substantial volumes of sensitive corporate and personal data and, in some incidents, released the data in full or in large tranches. This behavior is consistent with data-theft extortion and leak-site pressure, and available reporting also indicates file encryption as part of its ransomware operations. Attribution around some campaigns has been noisy. Early reporting initially suspected that attacks exploiting Cleo managed file transfer vulnerabilities were the work of a new group called Termite, but later reporting attributed that campaign to Clop instead. This suggests that some activity initially associated with Termite may have reflected misattribution or branding confusion rather than confirmed Termite operations. More broadly, Termite has been cited as part of a fragmented ransomware ecosystem composed of smaller, shorter-lived crews rather than the earlier dominant cartel-style brands. No high-confidence state sponsorship is established from the available facts. The actor is best assessed as a financially motivated cybercriminal ransomware operation focused on extortion through a combination of data theft, public shaming via a leak site, and at least in some cases file encryption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as the threat group responsible for a ransomware attack and data breach against Affinia Healthcare.
Named as the ransomware group responsible for the attack against JD Young.
Conducting a ransomware attack resulting in a data breach against Cal Fresh.
Conducting a ransomware attack against Wiese USA, a manufacturing-sector company in the United States.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.