Finally, there’s a memory-only dropper that fetches the above payloads and loads them, called Termite.
Termite
TERMITE is a password-protected, memory-only PowerShell dropper associated with UNC2596 (Cuba ransomware) intrusions.
Profile source: Mallory opens in a new tabTermite
Family profile
TERMITE is a password-protected, memory-only PowerShell dropper associated with UNC2596 (Cuba ransomware) intrusions. It uses obfuscated PowerShell to execute embedded encrypted shellcode in memory, then retrieves additional shellcode and encrypted payloads from command-and-control infrastructure. The subsequent shellcode decrypts and reflectively loads payloads without requiring their conventional installation on disk. TERMITE has been used to deploy BUGHATCH, Cobalt Strike Beacon, and a Metasploit stager during Cuba ransomware operations. UNC2596 commonly used TERMITE after obtaining access to vulnerable public-facing Microsoft Exchange servers and establishing a foothold with web shells or backdoors. The TERMITE name has also been applied to unrelated malware and ransomware activity; those uses should not be conflated with the Cuba-associated PowerShell dropper.
Capabilities
- Defense Evasion
- Post Exploitation
Reported operators
Threat actors
2 named in public reportingThreat hunters disclosed multiple ClickFix campaigns, including one leading to a hands-on-keyboard attack that deployed the Termite ransomware.
MITRE ATT&CK