termite
- First seen
- 2017-08-01 00:00:00
- Malware type
- trojan, rat
- Family
- Malware family
- Last IoC activity
- 2026-06-24 05:25:04
- Profile updated
- 2026-07-07 13:22:06
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:cn
Context
Termite is a remote access trojan used primarily for cyber espionage, targeting government and technology sectors. It is known for its versatility and ability to run commands on infected systems, facilitating data exfiltration to command and control servers.
Detection coverage
- 1 YARA rules
Used by threat actors
- Cleo File Transfer Software Zero-Day Exploits (CVE-2024-50623 & CVE-2024-55956) (campaign)
Detection rules
- MALPEDIA_Win_Termite_Auto (yara-rule)
Reports & references
- Mandiant — Evolution Of Fin7 (report)
- ransomlook.io — Termite (report)
- threatrecon.nshc.net — Sectorm04 Targeting Singapore Custom Malware Analysis (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Termite (report)
- alienvault.com — Internet Of Termites (report)