Termite is a financially motivated ransomware group using modified Babuk code to target supply chains.
Analyst brief
Termite is a financially motivated ransomware group first observed in late 2024, utilizing a modified version of the Babuk ransomware code. The group primarily targets entities in the United States, China, Canada, and Australia, focusing on the manufacturing, healthcare, agriculture, and food production sectors. Key TTPs include data exfiltration and encryption via custom ransomware, with a notable supply-chain attack on software firm Blue Yonder leading to the theft of 680 GB of data and disruption of major customers. Defenders should prioritize supply-chain risk management for critical software vendors and implement defenses against known Babuk-based ransomware TTPs.
termite
activecrime
Termite is a ransomware group first identified in late 2024 using a modified version of Babuk ransomware code; its most notable attack was the November 2024 breach of supply-chain software firm Blue Yonder, claiming 680 GB of exfiltrated data and disrupting major customers including Starbucks.
observed victims (by country)
United StatesChinaCanadaAustralia
observed sectors
ManufacturingHealthcareNot FoundAgriculture and Food Production