TERMITE is a password-protected, memory-only malware dropper associated most notably with UNC2596/Cuba ransomware intrusions. It contains encrypted shellcode and is used to fetch and load additional payloads directly in memory, including BUGHATCH, Cobalt Strike BEACON, and Metasploit stagers, helping operators avoid writing tooling to disk. In Cuba-linked operations, TERMITE has been used after initial compromise of public-facing Microsoft Exchange servers, alongside web shells and other backdoors, as part of a broader intrusion set supporting persistence, privilege escalation, lateral movement, data exfiltration, and ransomware deployment.
TERMITE has also been used as a label for a Linux backdoor observed in attacks against Sophos Firewall devices following exploitation of CVE-2022-3236. In that context, the malware was identified as a UPX-packed ELF remote-access tool capable of command execution and SOCKS proxying on compromised network appliances. Because the same name has been applied to both a Windows memory-only dropper and a Linux RAT/backdoor in separate reporting, TERMITE should be treated as an overloaded designation rather than a single, consistently defined malware family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Finally, there’s a memory-only dropper that fetches the above payloads and loads them, called Termite.
Threat hunters disclosed multiple ClickFix campaigns, including one leading to a hands-on-keyboard attack that deployed the Termite ransomware.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware is a typical backdoor with the added functionality of being able to serve as a SOCKS proxy, which would allow it to intercept the contents of some kinds of web traffic.
The following analytic detects modifications to files with extensions commonly associated with ransomware... This activity is significant because it suggests an attacker is attempting to encrypt or alter files... If this is a true ransomware attack, there will be a large number of files created with these extensions.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware referenced as having impacted Blue Yonder, with downstream effects on Starbucks.
"Termite ransomware breaches linked to ClickFix CastleRAT attacks"
Ransomware deployed following ClickFix-driven social engineering and hands-on-keyboard intrusion activity.
Ransomware deployed following a ClickFix-driven intrusion culminating in hands-on-keyboard activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.