logo

Termite ransomware breaches linked to ClickFix CastleRAT attacks

ID: 500bd238-03a6-5a07-b198-7f3295a6097c

STIX ID: report--500bd238-03a6-5a07-b198-7f3295a6097c

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers at MalBeacon observed Velvet Tempest (DEV-0504) conduct a 12-day intrusion in an emulated nonprofit environment using a malvertising-driven ClickFix lure that convinced victims to paste obfuscated commands into the Windows Run dialog; operators executed nested cmd chains and legitimate Windows utilities (finger.exe, csc.exe, PowerShell) to stage DonutLoader and retrieve the CastleRAT backdoor, harvested Chrome credentials, and performed AD reconnaissance and host discovery — the group is a longstanding ransomware affiliate associated with multiple major ransomware families, though Termite ransomware was not deployed in this observed engagement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.