Termite is a ransomware and data-extortion operation publicly associated with victim claims since late 2024. The group maintains a leak-site identity, but a listing alone does not establish that its operators or malware were involved in a named victim’s incident. Public monitors have warned that some listings attributed to Termite may be unverified or fabricated.
Activity and targeting
Splunk Threat Research Team described Termite claims and reported activity involving organizations in supply-chain technology, fertility services, consumer products, trucking, shipping and food services. That record supports cross-sector activity but should not be read as a complete or independently verified victim list.
Methods and operational characteristics
Splunk analyzed a Termite ransomware sample that can stop security and backup services, terminate applications, delete shadow copies, enumerate network shares and mapped or remote drives, encrypt local and network-accessible data and place ransom notes alongside affected files. Those are family-level capabilities and do not establish that the same payload or techniques were used in every incident claimed under the Termite name.
What type of group is it?
Termite is best characterized as a financially motivated ransomware and extortion brand. Its encryption functions, ransom-note behavior and victim-publication activity are consistent with ransomware-enabled extortion. The reviewed sources do not establish the operators’ identities, location, affiliate structure, state sponsorship or continuity of personnel, and the reliability warning attached to some later listings requires incident-by-incident corroboration.