Skip to content

Termite

TERMITE is a password-protected, memory-only PowerShell dropper associated with UNC2596 (Cuba ransomware) intrusions.

Profile source: Mallory opens in a new tab

Termite

Family profile

TERMITE is a password-protected, memory-only PowerShell dropper associated with UNC2596 (Cuba ransomware) intrusions. It uses obfuscated PowerShell to execute embedded encrypted shellcode in memory, then retrieves additional shellcode and encrypted payloads from command-and-control infrastructure. The subsequent shellcode decrypts and reflectively loads payloads without requiring their conventional installation on disk. TERMITE has been used to deploy BUGHATCH, Cobalt Strike Beacon, and a Metasploit stager during Cuba ransomware operations. UNC2596 commonly used TERMITE after obtaining access to vulnerable public-facing Microsoft Exchange servers and establishing a foothold with web shells or backdoors. The TERMITE name has also been applied to unrelated malware and ransomware activity; those uses should not be conflated with the Cuba-associated PowerShell dropper.

Capabilities

  • Defense Evasion
  • Post Exploitation

Reported operators

Threat actors

2 named in public reporting
RomCom

Finally, there’s a memory-only dropper that fetches the above payloads and loads them, called Termite.

Velvet Tempest

Threat hunters disclosed multiple ClickFix campaigns, including one leading to a hands-on-keyboard attack that deployed the Termite ransomware.

MITRE ATT&CK

Termite in ATT&CK

8 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.