Termite Ransomware Group Adopts ClickFix Tactics to Deploy CastleRAT
Mar 7, 2026 // 19:39 - Norina Velotta


Security researchers have linked recent Termite ransomware breaches to an attack chain involving ClickFix social engineering and the CastleRAT backdoor. The activity is attributed to Velvet Tempest (also known as DEV-0504), a notorious ransomware affiliate previously tied to groups like Conti and LockBit.

The Attack Chain

The infection relies on tricking users into compromising their own systems:

  • ClickFix Social Engineering: Victims land on compromised sites showing fake errors (like a “Chrome update failed” pop-up).
  • The “Fix”: Users are prompted to copy a malicious PowerShell script and run it via the Windows Run dialog to “repair” the browser.
  • CastleRAT Entry: This command installs CastleRAT, giving attackers remote control over the network.
  • Termite Deployment: After lateral movement, the attackers deploy Termite, a ransomware strain built on the leaked Babuk source code.

Impact and Notoriety

This specific campaign gained global attention after being linked to the November 2024 attack on Blue Yonder, a supply chain software giant. The breach caused significant disruptions for major retailers like Starbucks and Sainsbury’s by knocking out automated scheduling and inventory systems.

Protection Tips

  • User Training: Teach staff that legitimate websites will never ask them to paste code into a terminal or “Run” box.
  • PowerShell Monitoring: Set up alerts for unusual PowerShell activity, especially commands involving Base64 encoding or internet-facing downloads.
  • Endpoint Defense: Ensure EDR tools are configured to block suspicious child processes originating from web browsers.

#“clickfix”  #adopts  #castlerat  #deploy  #group  #news  #ransomware  #tactics  #termite   —   News