Classification: TLP:CLEAR | Publication Date: 2026-09-26 | Source: ransomware.live leak-site monitoring (single-source for some listings — see Sourcing & Verification) | Nature of data: Unverified threat-actor claims
TERMITE Ransomware Gang: 4 New Leak-Site Listings in 4 Days — US-Only Targeting, Sector Analysis & Detection Rules
Executive Summary
Between 2026-09-22 and 2026-09-25, the ransomware group tracked as TERMITE listed four organizations on its dark web leak site, all located in the United States: Crossett, Sealcon, theLender, and TruAmerica Multifamily. The listings span manufacturing, financial services, and real estate/multifamily sectors, with one listing carrying no reliably identified sector classification.
These are unverified claims by a criminal actor. A leak-site posting is an accusation, not a confirmed breach, and none of these listings has been corroborated by a second independent crawler at time of publication. That said, even unverified leak-site activity is a useful defensive signal: it tells us which sectors and geographies the gang is currently presenting as its hunting ground, and it gives named organizations a heads-up to validate internally rather than learn of a claim from a journalist.
Key takeaways for defenders:
- TERMITE is currently presenting a US-exclusive victim set in this window — US-based mid-market organizations should treat this as a heightened-exposure period.
- Financial services and manufacturing appear in the claimed victim mix, consistent with the gang's historical preference for sectors where downtime and regulatory exposure maximize extortion pressure.
- The compressed posting cadence (three listings on a single day, 2026-09-22) is consistent with either a batch detonation event or a deliberate publicity push — both warrant elevated monitoring.
- No CVE can be tied to any specific named organization in this data. We discuss currently-exploited vulnerabilities below strictly as sector-level exposure hypotheses, not as attribution for any listing.
Sourcing & Verification
This briefing is built from leak-site monitoring data and must be read with the following caveats:
- Corroboration status: 0 of 4 listings were independently observed by a second leak-site crawler. All 4 listings (Crossett, Sealcon, theLender, TruAmerica Multifamily) are single-source — they appear on ransomware.live only, with no second-crawler confirmation that the posting even exists on the gang's site.
- What inclusion means: A listing reflects the threat actor's claim and nothing more. It is NOT confirmation of a breach, an intrusion, or data theft. No corroboration tier in our data confirms a breach — only the organization itself or its regulator can do that.
- Disputes and denials: A named organization may dispute the listing. A denial is likewise not proof the claim is false — disclosure obligations vary by jurisdiction, sector, and data type, and not every incident is legally reportable. Neither silence nor denial settles the question, and we do not treat either as evidence in either direction.
- Corrections: Security Arsenal will publish corrections promptly if listings are removed, retracted, or credibly disputed. We welcome contact from any named organization at security@securityarsenal.com.
Threat Actor Profile — TERMITE
Model: TERMITE operates as a closed or semi-closed ransomware operation rather than a fully open RaaS program with a large public affiliate base, based on observed operational patterns. The group maintains its own Tor-based leak site where it names victims and threatens data publication — a classic double extortion model in which encryption is paired with the threat of leaking stolen data to force payment even from victims with viable backups.
Aliases: No widely adopted aliases are associated with the group in public reporting at this time; we track it under the name it uses on its own infrastructure.
Ransom demands: Consistent with mid-tier ransomware operations, demands are understood to scale to perceived victim revenue — typically ranging from the low six figures to low seven figures USD, payable in cryptocurrency. Initial demands are frequently inflated 2–3x above what the group will accept in negotiation.
Initial access methods (historical pattern, not tied to any listing in this brief):
- Exploitation of internet-facing remote access services — VPN concentrators, firewalls, and remote management gateways
- Phishing with malicious attachments or links leading to loader malware
- RDP exposure — brute-forced or purchased credentials from access brokers
- Occasional reliance on initial access brokers (IABs) rather than self-generated access
Dwell time: Mid-tier groups of this profile typically operate with dwell times of days to roughly two weeks between initial access and detonation, using the interval for credential theft, lateral movement, and staging data for exfiltration. The cluster of three same-day listings on 2026-09-22 is consistent with a gang that runs parallel intrusions and detonates or publishes in batches.
Extortion approach: Double extortion — victims are named on the leak site with countdown timers, followed by staged data release if payment is not made. Named organizations should assume that any genuine compromise would involve both encryption and data theft claims.
Current Campaign Analysis
Claimed victim set (2026-09-22 to 2026-09-25)
| Organization | Claimed Sector | Country | Listed | Corroboration |
|---|---|---|---|---|
| Crossett | Other | US | 2026-09-25 | Single-source |
| Sealcon | Manufacturing | US | 2026-09-22 | Single-source |
| theLender | Financial Services | US | 2026-09-22 | Single-source |
| TruAmerica Multifamily | Not Found | US | 2026-09-22 | Single-source |
Sector targeting
The claimed mix — manufacturing, financial services, and multifamily real estate — matches the mid-market extortion playbook: organizations with meaningful revenue, heavy operational-continuity pressure, and (in the case of financial services and property management) large volumes of personally identifiable information and financial records that amplify leak-based leverage. Manufacturing remains attractive because production downtime creates immediate financial pain and negotiation urgency.
Geographic concentration
100% United States in this window. US-targeting maximizes both ransom potential (higher ability to pay) and regulatory pressure (state breach notification laws, sector regulators) that criminals exploit as psychological leverage.
Victim profile
Based on the sectors claimed, the profile skews toward mid-market enterprises — organizations large enough to pay six-to-seven-figure demands but often below the security maturity of Fortune 500 peers. Multifamily real estate and specialty lending firms in particular frequently run lean IT teams, legacy remote access infrastructure, and flat networks — all favorable conditions for a mid-tier ransomware crew.
Posting cadence and escalation pattern
Four listings in four days, with three posted on a single day (2026-09-22), suggests either batch detonation after parallel intrusions or a coordinated publicity push to raise the group's profile. Groups at this maturity level often surge posting activity when attempting to attract affiliates or establish brand credibility. Defenders should watch for a follow-on wave in the coming 2–3 weeks.
Vulnerability exposure context (hypothesis only)
We have no evidence linking any specific CVE to any named listing above. However, given TERMITE's historical reliance on edge-device and remote-access exploitation, the following CISA KEV entries with confirmed ransomware use represent the exposure classes defenders in the targeted sectors should treat as priority patch candidates:
- CVE-2026-50751 — Check Point Security Gateway improper authentication (IKEv1 key exchange): perimeter gateway compromise is a classic ransomware entry point.
- CVE-2026-20316 — Cisco Secure Firewall Management Center hard-coded password: management-plane compromise of network security infrastructure.
- CVE-2026-59310 — Broadcom VMware vCenter path traversal: hypervisor management-plane access enables mass encryption of virtualized estates — the highest-impact single target in most mid-market environments.
- CVE-2026-63077 — JetBrains TeamCity deserialization: CI/CD server compromise enables supply-chain-style lateral movement and credential harvesting from build pipelines.
- CVE-2026-48027 — Nx Console embedded malicious code: developer workstation tooling compromise as a foothold into engineering environments.
Hypothesis framing only: if TERMITE's current wave used any of these, the most plausible candidates given their historical profile are the perimeter/VPN and vCenter classes — but this is sector-level exposure analysis, not victim-specific attribution.
Detection Engineering
The detections below target TTPs consistent with this gang's known playbook: edge/remote-access initial access, phishing-driven macro execution, RDP-based lateral movement, PsExec/WMI abuse, Cobalt Strike-style beaconing, and pre-encryption data staging and shadow copy deletion.
---
title: Suspicious Office Macro Spawning Script Interpreter or Payload
description: Detects Office applications spawning script interpreters or download cradles, consistent with phishing-delivered loader execution used by mid-tier ransomware groups for initial access.
status: experimental
logsource:
category: process_creation
product: windows
detection_placeholder: null
detection:
selection_parent:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\outlook.exe'
selection_child:
Image|endswith:
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\cmd.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate Office add-ins and templates
level: high
tags:
- attack.initial_access
- attack.t1566.001
- attack.t1059
---
title: PsExec-Style Remote Service Creation or WMI Lateral Movement
description: Detects service installation events and WMI process creation indicative of PsExec-style or WMI-based lateral movement, a hallmark of ransomware hands-on-keyboard phases prior to detonation.
status: experimental
logsource:
product: windows
service: system
detection:
selection_service:
EventID: 7045
ServiceName|contains:
- 'PSEXESVC'
- 'PAExec'
- 'RemCom'
ImagePath|contains:
- '\ADMIN$'
- '\IPC$'
- 'PSEXESVC'
selection_wmi:
EventID: 7045
ServiceFileName|contains: 'svchost.exe -k'
condition: selection_service
falsepositives:
- Legitimate administrative tooling (SCCM, PDQ, ManageEngine) — baseline and whitelist known admin service names
level: high
tags:
- attack.lateral_movement
- attack.t1021.002
- attack.t1569.002
- attack.t1047
---
title: Pre-Ransomware Staging - Shadow Copy Deletion and Backup Tampering
description: Detects Volume Shadow Copy deletion, boot configuration tampering, and catalog clearing that ransomware operators perform immediately before encryption to frustrate recovery.
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection_vss:
Image|endswith:
- '\vssadmin.exe'
- '\wmic.exe'
CommandLine|contains:
- 'delete shadows'
- 'shadowcopy delete'
- 'resize shadowstorage'
selection_bcd:
Image|endswith: '\bcdedit.exe'
CommandLine|contains:
- 'recoveryenabled no'
- 'ignoreallfailures'
selection_wbadmin:
Image|endswith: '\wbadmin.exe'
CommandLine|contains:
- 'delete catalog'
- 'delete backup'
condition: 1 of selection_*
falsepositives:
- Backup administrators performing maintenance
- Storage capacity management scripts
level: critical
tags:
- attack.impact
- attack.t1490
- attack.defense_evasion
The following Sentinel hunt query surfaces the lateral movement and pre-staging pattern: new admin-share service execution combined with remote logons, a common signature in the 24–72 hours before a ransomware detonation event.
// Hunt: Lateral movement & pre-ransomware staging indicators
// Correlates remote logons, admin$ service installs, and shadow-copy tampering per device
let lookback = 7d;
let RemoteLogons =
SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 4624 and LogonType in (3, 10)
| where Account !endswith "$" and Account !in ("SYSTEM", "ANONYMOUS LOGON")
| summarize RemoteLogonCount = count(), Sources = make_set(IpAddress) by Computer, Account, bin(TimeGenerated, 1h);
let SuspiciousServices =
Event
| where TimeGenerated > ago(lookback)
| where EventLog == "System" and EventID == 7045
| where EventData has_any ("PSEXESVC", "ADMIN$", "PAExec", "RemCom")
| summarize ServiceInstalls = count(), ServiceNames = make_set(EventData) by Computer, bin(TimeGenerated, 1h);
let ShadowTampering =
SecurityEvent
| where TimeGenerated > ago(lookback)
| where EventID == 4688
| where Process has_any ("vssadmin", "bcdedit", "wbadmin")
| where CommandLine has_any ("delete shadows", "recoveryenabled no", "delete catalog", "resize shadowstorage")
| summarize TamperEvents = count(), Cmds = make_set(CommandLine) by Computer, bin(TimeGenerated, 1h);
RemoteLogons
| join kind=inner SuspiciousServices on Computer, TimeGenerated
| join kind=leftouter ShadowTampering on Computer, TimeGenerated
| project Computer, Account, RemoteLogonCount, Sources, ServiceInstalls, TamperEvents, Cmds, TimeGenerated
| sort by TamperEvents desc, ServiceInstalls desc;
This rapid-response PowerShell script gives responders a fast triage of the most common pre-detonation artifacts: recently created scheduled tasks, RDP exposure, shadow copy state, and recently created local accounts.
# rapid-triage.ps1 - Run elevated. Triage for pre-ransomware staging artifacts.
# Outputs to C:\IR-Triage-<hostname>.txt
$out = "C:\IR-Triage-$env:COMPUTERNAME.txt"
"=== RAPID RANSOMWARE TRIAGE: $env:COMPUTERNAME - $(Get-Date) ===" | Out-File $out
"`n--- [1] Scheduled tasks created in last 7 days ---" | Out-File $out -Append
Get-ScheduledTask | Where-Object { $_.Date -and ([datetime]$_.Date) -gt (Get-Date).AddDays(-7) } |
Select-Object TaskName, TaskPath, Date, @{N='Action';E={$_.Actions.Execute}} |
Format-Table -AutoSize | Out-String | Out-File $out -Append
"`n--- [2] RDP exposure check ---" | Out-File $out -Append
$rdp = Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -ErrorAction SilentlyContinue
"RDP Enabled: $(if($rdp.fDenyTSConnections -eq 0){'YES - REVIEW NECESSITY'}else{'Disabled'})" | Out-File $out -Append
Get-NetTCPConnection -LocalPort 3389 -State Listen -ErrorAction SilentlyContinue |
Format-Table LocalAddress, LocalPort, State | Out-String | Out-File $out -Append
"`n--- [3] Volume Shadow Copies present? (absence on a server = red flag) ---" | Out-File $out -Append
$shadows = Get-CimInstance Win32_ShadowCopy -ErrorAction SilentlyContinue
if ($shadows) { $shadows | Select-Object ID, InstallDate, VolumeName | Format-Table | Out-String | Out-File $out -Append }
else { "WARNING: NO SHADOW COPIES FOUND - possible vssadmin deletion (T1490)" | Out-File $out -Append }
"`n--- [4] Local accounts created in last 7 days ---" | Out-File $out -Append
Get-LocalUser | Where-Object { $_.Created -gt (Get-Date).AddDays(-7) } |
Select-Object Name, Enabled, Created | Format-Table | Out-String | Out-File $out -Append
"`n--- [5] New services installed in last 7 days (Event 7045) ---" | Out-File $out -Append
Get-WinEvent -FilterHashtable @{LogName='System'; Id=7045; StartTime=(Get-Date).AddDays(-7)} -ErrorAction SilentlyContinue |
Select-Object TimeCreated, Message | Format-List | Out-String | Out-File $out -Append
"`nTriage complete: $out" | Out-File $out -Append
Incident Response Priorities
T-minus detection checklist — catch it before encryption fires
Groups with TERMITE's profile are most detectable in the hours-to-days window between staging and detonation. Hunt for:
- Backup and recovery tampering —
vssadmin delete shadows,bcdeditrecovery disabling, backup catalog deletion (T1490). This is the single highest-fidelity pre-detonation signal. - Mass file staging for exfiltration — large archive creation (7-Zip, WinRAR) in user directories,
rcloneor MEGASync-style tooling appearing on servers, sustained outbound transfers to unfamiliar cloud storage or VPS IPs. - Lateral movement burst — sudden spike in PsExec/service installs (Event 7045), WMI process creation, or SMB admin-share access from a single workstation to many servers.
- Credential dumping artifacts —
lsass.exememory access by non-system processes,ntds.ditcopies, procdump usage. - Security tool interference — EDR/AV service stops, tamper attempts,
wevtutil cllog clearing, new GPOs pushing suspicious scripts. - New persistence — scheduled tasks, local admin accounts, or RMM tools (AnyDesk, ScreenConnect, Atera) installed in the last 7 days that IT cannot account for.
Assets this gang profile historically prioritizes for exfiltration
Based on the double-extortion model and the sectors claimed in this wave, assume the following are the primary theft targets:
- Financial and lending records — loan applications, borrower PII, banking details (acute for financial services listings such as the one naming theLender)
- Tenant and resident PII — leases, background checks, payment records (acute for multifamily/property-management environments)
- HR data — payroll, SSNs, benefits files
- Contracts and legal documents — used for targeted leak pressure
- Engineering/manufacturing IP — CAD files, process documentation, supplier terms
Containment actions, ordered by urgency
- Isolate, don't power off. Network-quarantine affected segments/hosts via EDR isolation or switch-level ACLs. Preserve volatile memory for forensics.
- Kill the command channel. Block identified C2 domains/IPs at egress; sinkhole known Cobalt Strike infrastructure; disable suspicious RMM agents enterprise-wide.
- Credential reset at scale. Reset all domain admin, service account, and any account that authenticated to a suspected host. Assume krbtgt compromise if DC access is suspected — plan for the double-reset procedure.
- Freeze remote access. Temporarily disable or tightly ACL VPN and RDP ingress; force MFA re-enrollment review; audit active sessions for impossible travel.
- Protect backups first. Verify backup infrastructure is segmented, immutable, and uncompromised before any recovery activity — attackers routinely detonate against backup catalogs first.
- Engage counsel and review notification obligations early. Even an unverified leak-site claim may trigger regulatory clocks or insurer notification requirements depending on jurisdiction and findings.
Hardening Recommendations
Immediate (24 hours)
- Patch the KEV perimeter set: prioritize CVE-2026-50751 (Check Point gateway) and CVE-2026-20316 (Cisco FMC) on any internet-facing appliance — these are the exposure classes most consistent with this gang's historical entry profile. Verify CVE-2026-59310 (vCenter) is remediated; vCenter compromise enables estate-wide encryption in minutes.
- Audit and restrict RDP: confirm no direct internet exposure (scan your own ranges), enforce VPN-first access with MFA, and enable account lockout plus NLA.
- Deploy the Sigma rules above for macro-spawned interpreters, PsExec/WMI service creation, and shadow-copy tampering — route the T1490 rule to paging/on-call.
- Verify backup immutability: confirm offline/immutable copies, test one restore, and lock backup console access behind phishing-resistant MFA.
- Hunt for unauthorized RMM tools (AnyDesk, ScreenConnect, Atera, Splashtop) and block their executables where not sanctioned.
Short-term (2 weeks)
- Segment the estate: isolate server VLANs from workstations, restrict SMB/RPC lateral paths (disable SMBv1, restrict admin$ access to designated admin hosts), and place backup infrastructure in a separate trust zone.
- Deploy application control (WDAC/AppLocker) on servers to block unauthorized archivers (rar, 7z), tunneling tools, and rclone-style exfil utilities.
- Egress filtering and DLP on bulk transfer: alert on outbound transfers above baseline to unsanctioned cloud storage, and block known exfil destinations.
- Phishing-resistant MFA everywhere — especially VPN, email, and any remote management plane (vCenter, firewall managers). TERMITE-profile crews live on stolen credentials.
- Stand up the KQL hunt as a scheduled analytic rule in Sentinel with entity-based alerting, and run the triage script across critical servers as a baseline exercise.
- CI/CD and developer tooling review: remediate CVE-2026-63077 (TeamCity) and CVE-2026-48027 (Nx Console) exposure, rotate any secrets stored in build pipelines, and treat developer workstations as privileged assets.
Related Resources
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.