The recent ransomware attack on Blue Yonder, which affected major companies such as Starbucks, Sainsbury's and Morrisons, is reportedly linked to a relatively new group called Termite.

The Termite group claims to have stolen 680GB of data, including more than 16,000 email lists (which are to be used for future attacks) and 200,000 insurance documents.
Blue Yonder says it is working with cybersecurity to investigate the allegations.
Termite has claimed responsibility for attacks against organizations in various sectors (government agencies, oil and gas companies, and automotive industries). It has reported at least 10 victims worldwide, although many have yet to confirm whether they were the target of a ransomware attack. The group appears to be primarily focused on Europe and North America and has been active since April 2024.
See also: Anna Jaques Hospital: Ransomware attack exposed patient data
A possible new Babuk variant
Cyble analysts have analyzed binaries from the ransomware implant used by the Termite group and believe it is likely a rebranding of the infamous Babuk ransomware.
Broadcom has also linked the Termite ransomware to Babuk, noting the Termite group logo.
It is worth noting that a few days ago, Russian authorities arrested Mikhail Pavolvich Matveev, also known as WazaWaka. In 2023, the US had targeted him as the leader of the Babuk ransomware group.
How Termite Ransomware infects devices
During execution, Termite ransomware uses the SetProcessShutdownParameters API to delay system shutdown and maximize encryption time. It also attempts to stop services on the victim's computer by connecting the Service Control Manager to the OpenSCManagerA() API. This prevents potential interruptions during encryption.
See also: Deloitte denies ransomware breach on its network
The ransomware controls the services on the victim's computer and looks for Microsoft's Virtual Machine Management Service (VMMS) or virtual machine backup and recovery systems, such as those from Veeam.
The ransomware controls running processes and terminates them.
It then runs multiple processes to prevent system recovery and delete all files from the Recycle Bin, to ensure that the victim cannot recover any files after encryption.

After encrypting files on the victim’s computer, it appends the extension “.termite.”
Like Babuk ransomware, Termite also appends the signature “choung dong looks like hot dog” to the end of the encrypted file.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
After scanning for processors running on the targeted device, the Termite ransomware creates a ransom note for each CPU, titled “How To Restore Your Files.txt“.
See also: Ransomware attacks are draining small businesses
Ransomware protection
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using solutions email security for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Back up your data regularly
- Stay up to date on the latest ransomware trends and tactics used by attackers
Source: www.infosecurity-magazine.com
