logo

New 'Termite' Ransomware Hits Blue Yonder: A Technical Look

ID: 9622a43e-a939-5c77-b1b5-ea6be3e7c01c

STIX ID: report--9622a43e-a939-5c77-b1b5-ea6be3e7c01c

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-07-17

...
...

**Executive summary:** This Cyble CRIL report analyzes the Termite ransomware (a Babuk rebrand) that impacted supply-chain management platform Blue Yonder, detailing its technical behavior — process and service termination, shadow copy and recycle-bin deletion, multi-threaded encryption adding a .termite extension and distinctive signature, propagation via network shares/paths, and double-extortion tactics — and provides MITRE ATT&CK mappings, a SHA-256 IoC, and recommended mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.