Termite
Termite is a ransomware/extortion group active by at least 2025 and tracked in reporting as a small, newer crew within a fragmented ransomware ecosystem. The group has been associated with double-extortion style activity, including claiming data theft, operating a dark web leak site, and in some cases publishing large multi-part data dumps. Broadcom stated that Termite ransomware encrypts victim files and directs victims to a dark web site to communicate about ransom payment. SentinelLABS cited Termite as one of several small, short-lived ransomware crews proliferating alongside increased brand mimicry and false claims in the ecosystem. Victim reporting in the provided content links Termite to incidents affecting multiple sectors and countries. Reported victims include Genea, an Australian IVF and fertility provider; Insight Hospital and Medical Center in Chicago; MedHelp Clinics in the United States; and News-Press & Gazette Company (NPG), a Missouri-based media firm. Broadcom said Termite had targeted a wide range of countries and sectors, including victims in France, Canada, Germany, Oman, and the United States. Cybernews stated its Ransomlooker tool showed at least 23 organizations impacted by the Termite gang during the past year, including Blue Yonder. In the Genea incident, reporting attributed the attack to Termite and said the group claimed to have hundreds of gigabytes of stolen files. Court materials cited in reporting stated the attackers were present in Genea’s network for more than two weeks beginning on 31 January and exfiltrated 940.7 GB of data on 14 February. Genea said data published externally may have included contact details, Medicare numbers, medical histories, test results, medications, diagnoses, treatments, doctors’ notes, emergency contacts, and private health insurance details. Separate reporting said Termite posted proof of claims, screenshots of patient files, a file tree, and a downloadable archive of approximately 700 GB of Genea data. In the Insight Hospital and Medical Center case, Termite added the organization to its leak site on 24 February and claimed to have exfiltrated 360 GB of confidential data, approximately 900,000 files. Reporting states the group leaked the data in multiple parts, including .jpeg and .dcm medical-image files. In another reported healthcare incident, Termite claimed to have accessed and removed around 25 GB of internal data from MedHelp Clinics. In the NPG incident, Termite claimed theft of financial and tax data, revenue reports, Excel budget files, employment details, passport photos, and other corporate files. Cybernews researchers who reviewed a sample said it contained both personal and corporate information, including the passport of NPG’s owner and employees’ contact details and home addresses. The content also notes that the Cleo managed file transfer attacks were initially suspected to be the work of a new ransomware gang named Termite, but later reporting said Clop confirmed that operation was its own project. Based on the provided content, Termite should therefore not be confidently attributed to the Cleo exploitation campaign. Known alias in the provided content: termite.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Media & Entertainment
- Commercial & Professional Services
Where they target
Geographies tied to known operations.
- 🇺🇸 United States
Tradecraft
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware/extortion activity claiming exfiltration and public leaking of stolen data from a hospital.
Ransomware-style data extortion activity: claims theft of large volumes of sensitive hospital data and publishes it on a dark web leak site in multiple tranches (full data dump rather than limited proof).
Termite is a ransomware group targeting healthcare organizations, exfiltrating internal data and threatening public disclosure.
Termite is a small, short-lived ransomware crew operating under the radar as part of the post-mega-brand cartel ransomware ecosystem. They are part of a trend of splintered, agile groups leveraging new technologies and tactics.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.