diff --git a/detections/endpoint/common_ransomware_extensions.yml b/detections/endpoint/common_ransomware_extensions.yml index 04399dfab1..dccad051f8 100644 --- a/detections/endpoint/common_ransomware_extensions.yml +++ b/detections/endpoint/common_ransomware_extensions.yml @@ -1,7 +1,7 @@ name: Common Ransomware Extensions id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec version: '13' -date: '2025-03-25' +date: '2025-04-01' author: David Dorsey, Michael Haag, Splunk, Steven Dick status: production type: TTP @@ -70,6 +70,7 @@ tags: - Clop Ransomware - Ryuk Ransomware - Black Basta Ransomware + - Termite Ransomware asset_type: Endpoint mitre_attack_id: - T1485 diff --git a/detections/endpoint/common_ransomware_notes.yml b/detections/endpoint/common_ransomware_notes.yml index a4c7c22689..337057afa5 100644 --- a/detections/endpoint/common_ransomware_notes.yml +++ b/detections/endpoint/common_ransomware_notes.yml @@ -1,7 +1,7 @@ name: Common Ransomware Notes id: ada0f478-84a8-4641-a3f1-d82362d6bd71 version: '9' -date: '2025-03-14' +date: '2025-04-01' author: David Dorsey, Splunk status: production type: Hunting @@ -38,6 +38,7 @@ tags: - Clop Ransomware - Ryuk Ransomware - Black Basta Ransomware + - Termite Ransomware asset_type: Endpoint mitre_attack_id: - T1485 diff --git a/detections/endpoint/deleting_shadow_copies.yml b/detections/endpoint/deleting_shadow_copies.yml index 18fd56e395..1fffc40064 100644 --- a/detections/endpoint/deleting_shadow_copies.yml +++ b/detections/endpoint/deleting_shadow_copies.yml @@ -1,7 +1,7 @@ name: Deleting Shadow Copies id: b89919ed-ee5f-492c-b139-95dbb162039e version: '12' -date: '2025-03-25' +date: '2025-04-01' author: David Dorsey, Splunk status: production type: TTP @@ -83,6 +83,7 @@ tags: - Clop Ransomware - Medusa Ransomware - VanHelsing Ransomware + - Termite Ransomware asset_type: Endpoint mitre_attack_id: - T1490 diff --git a/detections/endpoint/high_process_termination_frequency.yml b/detections/endpoint/high_process_termination_frequency.yml index 1a0825a25d..e0253c41ce 100644 --- a/detections/endpoint/high_process_termination_frequency.yml +++ b/detections/endpoint/high_process_termination_frequency.yml @@ -58,6 +58,7 @@ tags: - Crypto Stealer - Snake Keylogger - Clop Ransomware + - Termite Ransomware asset_type: Endpoint mitre_attack_id: - T1486 diff --git a/detections/endpoint/ransomware_notes_bulk_creation.yml b/detections/endpoint/ransomware_notes_bulk_creation.yml index 6ea94a4912..0d6c5906c3 100644 --- a/detections/endpoint/ransomware_notes_bulk_creation.yml +++ b/detections/endpoint/ransomware_notes_bulk_creation.yml @@ -1,8 +1,8 @@ name: Ransomware Notes bulk creation id: eff7919a-8330-11eb-83f8-acde48001122 -version: '6' -date: '2025-03-14' -author: Teoderick Contreras +version: '7' +date: '2025-04-01' +author: Teoderick Contreras, Splunk status: production type: Anomaly description: The following analytic identifies the bulk creation of ransomware notes @@ -59,6 +59,7 @@ tags: - Medusa Ransomware - Black Basta Ransomware - Clop Ransomware + - Termite Ransomware asset_type: Endpoint mitre_attack_id: - T1486 diff --git a/detections/endpoint/windows_security_and_backup_services_stop.yml b/detections/endpoint/windows_security_and_backup_services_stop.yml index 34b07167b6..45b5ea65c1 100644 --- a/detections/endpoint/windows_security_and_backup_services_stop.yml +++ b/detections/endpoint/windows_security_and_backup_services_stop.yml @@ -1,7 +1,7 @@ name: Windows Security And Backup Services Stop id: 9c24aef6-cad9-4931-acce-74318aa5663b -version: 1 -date: '2025-02-07' +version: 2 +date: '2025-04-01' author: Teoderick Contreras, Splunk status: production type: TTP @@ -61,6 +61,7 @@ tags: - Ransomware - Compromised Windows Host - BlackMatter Ransomware + - Termite Ransomware asset_type: Endpoint mitre_attack_id: - T1490 diff --git a/lookups/ransomware_extensions_lookup.csv b/lookups/ransomware_extensions_lookup.csv index 6dfb767f49..9298a07091 100644 --- a/lookups/ransomware_extensions_lookup.csv +++ b/lookups/ransomware_extensions_lookup.csv @@ -303,4 +303,5 @@ Extensions,Name *.rhysida,Rhysida *.basta, BlackBasta *.vanhelsing,Vanhelsing -*.vanlocker,Vanhelsing \ No newline at end of file +*.vanlocker,Vanhelsing +*.termite,Termite \ No newline at end of file diff --git a/lookups/ransomware_notes_lookup.csv b/lookups/ransomware_notes_lookup.csv index 5ab10617c1..83a26350d3 100644 --- a/lookups/ransomware_notes_lookup.csv +++ b/lookups/ransomware_notes_lookup.csv @@ -72,4 +72,5 @@ read_it.txt,True *.README.txt, True *READ_ME_MEDUSA*.TXT,True How_to_back_files.HTML,True -CriticalBreachDetected.pdf,True \ No newline at end of file +CriticalBreachDetected.pdf,True +How To Restore Your Files.txt, True \ No newline at end of file diff --git a/stories/termite_ransomware.yml b/stories/termite_ransomware.yml new file mode 100644 index 0000000000..934d1b69c3 --- /dev/null +++ b/stories/termite_ransomware.yml @@ -0,0 +1,32 @@ +name: Termite Ransomware +id: 3dec6aec-3d1a-44f0-affc-31bb201eaec5 +version: 1 +date: '2025-04-01' +author: Teoderick Contreras, Splunk +status: production +description: Termite Ransomware is a malicious software strain that recently targeted the supply chain management platform Blue Yonder. + It is a sophisticated threat that employs a multi-stage attack strategy. It typically initiates infection via phishing campaigns or + compromised websites, exploiting system vulnerabilities to gain access. Once inside the network, Termite Ransomware escalates privileges + and deploys robust encryption algorithms to lock down critical files, rendering them inaccessible. A ransom note is then left, + instructing victims to pay, even though payment does not guarantee data recovery. The malware is engineered with + defense evasion techniques, such as anti-analysis and anti-virtual machine features, complicating detection and forensic analysis. +narrative: Termite Ransomware is a malicious software strain designed to infiltrate computer systems, encrypt files, + and demand ransom payments from victims. Like a colony of termites silently eating away at wood, this ransomware + spreads stealthily, often spreading through phishing emails, malicious attachments, or exploit kits. + Once activated, Termite Ransomware locks critical files using strong encryption, + rendering them inaccessible to users. Victims typically receive a ransom note demanding payment—usually in + cryptocurrency—to regain access to their files. However, paying the ransom does not guarantee file recovery, + and it often funds further cybercrime. To mitigate risks, users should maintain regular backups, avoid suspicious links, + and employ robust security measures such as antivirus software and endpoint protection. + Cybersecurity experts recommend not paying the ransom and instead seeking professional assistance to attempt data recovery. +references: +- https://www.bleepingcomputer.com/news/security/cisa-confirms-critical-cleo-bug-exploitation-in-ransomware-attacks/ +- https://www.darkreading.com/cyberattacks-data-breaches/termite-ransomware-behind-cleo-zero-day-attacks +tags: + category: + - Malware + product: + - Splunk Enterprise + - Splunk Enterprise Security + - Splunk Cloud + usecase: Advanced Threat Detection \ No newline at end of file