Termite ransomware breaches linked to ClickFix CastleRAT attacks

2026-03-08T01:23:27Zc0edc7a3c8feff1e6639c68f5496e5888706a1219431565f0e11fdaa2371ace8
AI-enabled attacksAPT (UAT-9244)Bing AICISACastleRATClickFixCoruna exploit kitDonutLoaderInstallFixTriZettoVelvet TempestWikipedia JavaScript wormWordPressbackdoordata breachhealthcareiOS exploitinfostealermalicious-GitHubplugin vulnerabilityransomwaresupply-chaintelecom-targetingzero-day

What happened

Multiple high-impact security events and active campaigns reported: Velvet Tempest (Termite ransomware) leveraging ClickFix/InstallFix social-engineering to deploy DonutLoader and CastleRAT backdoors; widespread use of AI by threat actors to scale and automate attacks (including Bing-promoted malicious GitHub repos); a 3.4M-record data breach at Cognizant TriZetto exposing healthcare data; CISA emergency guidance to patch three iOS flaws exploited via the Coruna exploit kit; active exploitation of a critical WordPress User Registration & Membership plugin vulnerability to create admin accounts

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
c0edc7a3c8feff1e6639c68f5496e5888706a1219431565f0e11fdaa2371ace8
Enrichment time
2026-03-08T01:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Termite ransomware breaches linked to ClickFix CastleRAT attacks · Baitaphish