Skip to content

Termite

Termite is a malware/ransomware name used in multiple reporting contexts.

Profile source: Mallory opens in a new tab

Termite

Family profile

Termite is a malware/ransomware name used in multiple reporting contexts. Sophos X-Ops identified a Linux backdoor detected as Linux/Gognt-O, a UPX-packed ELF binary, that logs the string "Termite (v [number]) starting..." and can also function as a SOCKS proxy. This malware was observed in attacks against Sophos Firewall devices running SFOS that began with exploitation of CVE-2022-3236. In that campaign, the threat actor deployed a mix of custom and commodity Linux malware, including trojanized SFOS Java and Perl components, Linux backdoors, and Gh0st RAT variants; the broader toolset supported credential theft, covert command execution, file operations, persistence, encrypted C2, and stealthy communications.

Separately, Mandiant describes TERMITE as a password-protected, memory-only dropper containing an encrypted shellcode payload. In COLDDRAW ransomware intrusions attributed to UNC2596, TERMITE was used to deliver BEACON, a Metasploit stager, or the BUGHATCH backdoor. Those intrusions frequently began with exploitation of public-facing Microsoft Exchange vulnerabilities, followed by webshell deployment or backdoors, credential abuse and theft, internal reconnaissance, lateral movement via RDP/SMB/PsExec, data exfiltration, and eventual COLDDRAW ransomware deployment.

Termite is also referenced as a ransomware family/group in multiple incident and detection contexts. Reporting cited ClickFix campaigns that led to hands-on-keyboard intrusions deploying Termite ransomware, including links to CastleRAT attacks. Termite ransomware was also reported in the November 2024 Blue Yonder incident that caused downstream impact to Starbucks, and Genea was reported as having experienced a ransomware attack by the Termite group. Splunk analytic stories associate Termite with common ransomware behaviors such as ransom note creation, suspicious ransomware-related file extensions, high-frequency process termination, and stopping backup or security services. High-confidence indicators directly mentioned in the content include the startup log string "Termite (v [number]) starting..." for the Linux/Gognt-O sample and the TERMITE in-memory dropper characterization as password-protected and memory-only.

Reported operators

Threat actors

2 named in public reporting
RomCom

"TERMITE is a password-protected memory-only dropper which contains an encrypted shellcode payload."

Velvet Tempest

Threat hunters disclosed multiple ClickFix campaigns, including one leading to a hands-on-keyboard attack that deployed the Termite ransomware.

MITRE ATT&CK

Termite in ATT&CK

6 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.