Tag: Termite ransomware breaches

Termite ransomware breaches linked to ClickFix CastleRAT attacks
News

Termite ransomware breaches linked to ClickFix CastleRAT attacks

Ransomware threat actors identified as Velvet Tempest are deploying the DonutLoader malware and the CastleRAT backdoor utilizing the ClickFix method and trustworthy Windows programs. Over the course of 12 days, researchers from the cyber-deception threat intelligence firm MalBeacon watched the hackers' activities in a simulated organizational setting. For at least five years, Velvet Tempest, also known as DEV-0504, has been an associate of ransomware assaults. Some of the most destructive ransomware strains, including Ryuk (2018–2020), REvil (2019–2022), Conti (2019–2022), BlackMatter, BlackCat/ALPHV (2021–2024), LockBit, and RansomHub, have been linked to the actor. MalBeacon saw the attack in a replica environment for a non-profit organization in the United States read more ...