{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/termite-ransomware/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["ransomware","endpoint-detection","file-modification","impact","Rhysida Ransomware","Prestige Ransomware","LockBit Ransomware","Medusa Ransomware","SamSam Ransomware","Clop Ransomware","Ryuk Ransomware","Black Basta Ransomware","Termite Ransomware","Interlock Ransomware","NailaoLocker Ransomware"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThis brief describes an analytic designed to detect ransomware activity by monitoring for specific file extension changes on endpoint filesystems. The detection focuses on \u003ccode\u003ecreated\u003c/code\u003e or \u003ccode\u003emodified\u003c/code\u003e file actions where the new file extension corresponds to patterns frequently used by various ransomware families. While ransomware attacks commonly involve initial access, execution, and privilege escalation, this analytic specifically targets the impact stage where encryption occurs. The presence of files with these extensions, especially in large volumes, indicates that an attacker is actively encrypting or altering critical data, rendering it inaccessible. This activity, first created in October 2019 and updated in July 2026, leverages Endpoint.Filesystem data models, notably from Sysmon EventID 11 (FileCreate) and EventID 23 (FileRename), and highlights the immediate and severe risk of data loss and operational disruption for organizations.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Access\u003c/strong\u003e: Adversary gains unauthorized entry into the victim's network, often through phishing, exploiting vulnerable public-facing applications, or abusing valid accounts.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eExecution\u003c/strong\u003e: Malicious ransomware payloads are delivered and executed on compromised systems, sometimes via remote services, user-driven execution, or scheduled tasks.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePersistence\u003c/strong\u003e: Ransomware establishes persistence mechanisms (e.g., modifying registry run keys, creating scheduled tasks) to maintain access and re-execute after system reboots.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDiscovery\u003c/strong\u003e: The ransomware binary enumerates local files, attached storage, and accessible network shares to identify valuable data for encryption.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDefense Evasion\u003c/strong\u003e: The ransomware may attempt to disable security software, delete shadow copies, or clear event logs to hinder detection and recovery efforts.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eEncryption\u003c/strong\u003e: The ransomware encrypts target files on local drives and accessible network shares, often employing strong cryptographic algorithms.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFile Renaming\u003c/strong\u003e: Encrypted files are renamed with distinct, proprietary extensions (e.g., \u003ccode\u003e.locked\u003c/code\u003e, \u003ccode\u003e.encrypt\u003c/code\u003e, \u003ccode\u003e.rnsm\u003c/code\u003e) to signify their encrypted status. This specific action is a key indicator for the detection rule.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRansom Note Deployment\u003c/strong\u003e: Ransom notes containing demands, payment instructions, and threats of data publication are dropped in affected directories or displayed to the user.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful ransomware attacks lead to the encryption of critical data, making it inaccessible to the victim organization. This can result in severe operational disruption, including system downtime, loss of business continuity, and potential financial costs associated with recovery efforts, ransom payments, and regulatory fines. Victims often face significant data recovery challenges and may lose unrecoverable data. While the number of victims and specific sectors are not detailed in this analytic, ransomware broadly targets organizations across all industries, aiming for maximum financial extortion.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnsure ingestion of filesystem activity logs, specifically Sysmon EventID 11 (FileCreate) and EventID 23 (FileRename), to populate the Endpoint.Filesystem data model node for comprehensive endpoint visibility.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect file rename operations targeting common ransomware extensions.\u003c/li\u003e\n\u003cli\u003eReview and implement correlation rules in your SIEM for Sysmon EventID 23 to identify a high volume of file renames occurring within a short timeframe, indicating bulk encryption activity by ransomware.\u003c/li\u003e\n\u003cli\u003eRegularly back up critical data offline and test recovery procedures to minimize the impact of successful encryption.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T18:59:34Z","date_published":"2026-07-28T18:59:34Z","id":"https://feed.craftedsignal.io/briefs/2026-07-common-ransomware-extensions/","summary":"This analytic identifies ransomware activity by detecting file creation or modification events on endpoint filesystems where the resulting file extensions match known ransomware patterns, potentially leading to significant data loss and operational disruption.","title":"Detection of Common Ransomware File Extension Modifications","url":"https://feed.craftedsignal.io/briefs/2026-07-common-ransomware-extensions/"}],"language":"en","title":"CraftedSignal Threat Feed - Termite Ransomware","version":"https://jsonfeed.org/version/1.1"}