
Security researchers have linked recent Termite ransomware breaches to an attack chain involving ClickFix social engineering and the CastleRAT backdoor. The activity is attributed to Velvet Tempest (also known as DEV-0504), a notorious ransomware affiliate previously tied to groups like Conti and LockBit.
The Attack Chain
The infection relies on tricking users into compromising their own systems:
Impact and Notoriety
This specific campaign gained global attention after being linked to the November 2024 attack on Blue Yonder, a supply chain software giant. The breach caused significant disruptions for major retailers like Starbucks and Sainsbury’s by knocking out automated scheduling and inventory systems.
Protection Tips
Base64 encoding or internet-facing downloads.#“clickfix” #adopts #castlerat #deploy #group #news #ransomware #tactics #termite — News
© Bulletproof Servers. All rights reserved.