Termite ransomware breaches linked to ClickFix CastleRAT attacks

2026-03-07T19:23:31Zcedc9e1b49d7faea8de7117da686c3b630aae0e64bde65dddd9e0b9e48af367e
AI-assisted attacksBing AI misuseCISACastleRATClickFixCoruna exploit kitDonutLoaderGitHub malwareInstallFixJavaScript wormTriZettoUAT-9244Velvet TempestWikipedia incidentWordPress plugin exploitcrypto-theftdata breachhealthcare breachiOS vulnerabilitiesinfostealerransomwaresurveillance systems breachtelecom APTvulnerability managementzero-day exploitation

What happened

Multiple high-impact incidents and trends: ransomware group ‘Velvet Tempest’ (Termite) is using the ClickFix social-engineering method with legitimate Windows utilities to deploy DonutLoader and CastleRAT backdoors; a new InstallFix/ClickFix variant and malicious GitHub repos (promoted by AI search prompts) are distributing info-stealers and proxy malware; a critical vulnerability in the widely used WordPress User Registration & Membership plugin is being actively exploited to create admin accounts on ~60k sites; CISA directed federal patching for three iOS flaws exploited by the Coruna kit in

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
cedc9e1b49d7faea8de7117da686c3b630aae0e64bde65dddd9e0b9e48af367e
Enrichment time
2026-03-07T19:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.