Search

Termite Ransomware Using ClickFix and CastleRAT

Published March 7, 2026
High Active Ransomware

What Is This?

The Velvet Tempest group is deploying Termite ransomware through ClickFix social engineering techniques and legitimate Windows utilities. The attacks use DonutLoader malware and CastleRAT backdoor for persistence.

Affected Systems

Windows