New 'Termite' Ransomware Hits Blue Yonder: A Technical Look
ID: 9622a43e-a939-5c77-b1b5-ea6be3e7c01c
STIX ID: report--9622a43e-a939-5c77-b1b5-ea6be3e7c01c
Feed Name: Cyble Blog
**Executive summary:** This Cyble CRIL report analyzes the Termite ransomware (a Babuk rebrand) that impacted supply-chain management platform Blue Yonder, detailing its technical behavior — process and service termination, shadow copy and recycle-bin deletion, multi-threaded encryption adding a .termite extension and distinctive signature, propagation via network shares/paths, and double-extortion tactics — and provides MITRE ATT&CK mappings, a SHA-256 IoC, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
