mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
medusa_ransomware
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
name: Common Ransomware Extensions
|
||||
id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec
|
||||
version: '13'
|
||||
date: '2025-03-25'
|
||||
date: '2025-04-01'
|
||||
author: David Dorsey, Michael Haag, Splunk, Steven Dick
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -70,6 +70,7 @@ tags:
|
||||
- Clop Ransomware
|
||||
- Ryuk Ransomware
|
||||
- Black Basta Ransomware
|
||||
- Termite Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1485
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Common Ransomware Notes
|
||||
id: ada0f478-84a8-4641-a3f1-d82362d6bd71
|
||||
version: '9'
|
||||
date: '2025-03-14'
|
||||
date: '2025-04-01'
|
||||
author: David Dorsey, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
@@ -38,6 +38,7 @@ tags:
|
||||
- Clop Ransomware
|
||||
- Ryuk Ransomware
|
||||
- Black Basta Ransomware
|
||||
- Termite Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1485
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Deleting Shadow Copies
|
||||
id: b89919ed-ee5f-492c-b139-95dbb162039e
|
||||
version: '12'
|
||||
date: '2025-03-25'
|
||||
date: '2025-04-01'
|
||||
author: David Dorsey, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -83,6 +83,7 @@ tags:
|
||||
- Clop Ransomware
|
||||
- Medusa Ransomware
|
||||
- VanHelsing Ransomware
|
||||
- Termite Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1490
|
||||
|
||||
@@ -58,6 +58,7 @@ tags:
|
||||
- Crypto Stealer
|
||||
- Snake Keylogger
|
||||
- Clop Ransomware
|
||||
- Termite Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1486
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
name: Ransomware Notes bulk creation
|
||||
id: eff7919a-8330-11eb-83f8-acde48001122
|
||||
version: '6'
|
||||
date: '2025-03-14'
|
||||
author: Teoderick Contreras
|
||||
version: '7'
|
||||
date: '2025-04-01'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Anomaly
|
||||
description: The following analytic identifies the bulk creation of ransomware notes
|
||||
@@ -59,6 +59,7 @@ tags:
|
||||
- Medusa Ransomware
|
||||
- Black Basta Ransomware
|
||||
- Clop Ransomware
|
||||
- Termite Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1486
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
name: Windows Security And Backup Services Stop
|
||||
id: 9c24aef6-cad9-4931-acce-74318aa5663b
|
||||
version: 1
|
||||
date: '2025-02-07'
|
||||
version: 2
|
||||
date: '2025-04-01'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: TTP
|
||||
@@ -61,6 +61,7 @@ tags:
|
||||
- Ransomware
|
||||
- Compromised Windows Host
|
||||
- BlackMatter Ransomware
|
||||
- Termite Ransomware
|
||||
asset_type: Endpoint
|
||||
mitre_attack_id:
|
||||
- T1490
|
||||
|
||||
@@ -303,4 +303,5 @@ Extensions,Name
|
||||
*.rhysida,Rhysida
|
||||
*.basta, BlackBasta
|
||||
*.vanhelsing,Vanhelsing
|
||||
*.vanlocker,Vanhelsing
|
||||
*.vanlocker,Vanhelsing
|
||||
*.termite,Termite
|
||||
|
@@ -72,4 +72,5 @@ read_it.txt,True
|
||||
*.README.txt, True
|
||||
*READ_ME_MEDUSA*.TXT,True
|
||||
How_to_back_files.HTML,True
|
||||
CriticalBreachDetected.pdf,True
|
||||
CriticalBreachDetected.pdf,True
|
||||
How To Restore Your Files.txt, True
|
||||
|
@@ -0,0 +1,32 @@
|
||||
name: Termite Ransomware
|
||||
id: 3dec6aec-3d1a-44f0-affc-31bb201eaec5
|
||||
version: 1
|
||||
date: '2025-04-01'
|
||||
author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
description: Termite Ransomware is a malicious software strain that recently targeted the supply chain management platform Blue Yonder.
|
||||
It is a sophisticated threat that employs a multi-stage attack strategy. It typically initiates infection via phishing campaigns or
|
||||
compromised websites, exploiting system vulnerabilities to gain access. Once inside the network, Termite Ransomware escalates privileges
|
||||
and deploys robust encryption algorithms to lock down critical files, rendering them inaccessible. A ransom note is then left,
|
||||
instructing victims to pay, even though payment does not guarantee data recovery. The malware is engineered with
|
||||
defense evasion techniques, such as anti-analysis and anti-virtual machine features, complicating detection and forensic analysis.
|
||||
narrative: Termite Ransomware is a malicious software strain designed to infiltrate computer systems, encrypt files,
|
||||
and demand ransom payments from victims. Like a colony of termites silently eating away at wood, this ransomware
|
||||
spreads stealthily, often spreading through phishing emails, malicious attachments, or exploit kits.
|
||||
Once activated, Termite Ransomware locks critical files using strong encryption,
|
||||
rendering them inaccessible to users. Victims typically receive a ransom note demanding payment—usually in
|
||||
cryptocurrency—to regain access to their files. However, paying the ransom does not guarantee file recovery,
|
||||
and it often funds further cybercrime. To mitigate risks, users should maintain regular backups, avoid suspicious links,
|
||||
and employ robust security measures such as antivirus software and endpoint protection.
|
||||
Cybersecurity experts recommend not paying the ransom and instead seeking professional assistance to attempt data recovery.
|
||||
references:
|
||||
- https://www.bleepingcomputer.com/news/security/cisa-confirms-critical-cleo-bug-exploitation-in-ransomware-attacks/
|
||||
- https://www.darkreading.com/cyberattacks-data-breaches/termite-ransomware-behind-cleo-zero-day-attacks
|
||||
tags:
|
||||
category:
|
||||
- Malware
|
||||
product:
|
||||
- Splunk Enterprise
|
||||
- Splunk Enterprise Security
|
||||
- Splunk Cloud
|
||||
usecase: Advanced Threat Detection
|
||||
Reference in New Issue
Block a user