termite

First seen
2017-08-01 00:00:00
Malware type
trojan, rat
Family
Malware family
Last IoC activity
2026-06-24 05:25:04
Profile updated
2026-07-07 13:22:06

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:us country_code:cn

Context

Termite is a remote access trojan used primarily for cyber espionage, targeting government and technology sectors. It is known for its versatility and ability to run commands on infected systems, facilitating data exfiltration to command and control servers.

Detection coverage

  • 1 YARA rules

Used by threat actors

  • Cleo File Transfer Software Zero-Day Exploits (CVE-2024-50623 & CVE-2024-55956) (campaign)

Detection rules

  • MALPEDIA_Win_Termite_Auto (yara-rule)

Reports & references

  • Mandiant — Evolution Of Fin7 (report)
  • ransomlook.io — Termite (report)
  • threatrecon.nshc.net — Sectorm04 Targeting Singapore Custom Malware Analysis (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Termite (report)
  • alienvault.com — Internet Of Termites (report)

External references