Termite ransomware breaches linked to ClickFix CastleRAT attacks
2026-03-07T19:23:31Z•cedc9e1b49d7faea8de7117da686c3b630aae0e64bde65dddd9e0b9e48af367e
AI-assisted attacksBing AI misuseCISACastleRATClickFixCoruna exploit kitDonutLoaderGitHub malwareInstallFixJavaScript wormTriZettoUAT-9244Velvet TempestWikipedia incidentWordPress plugin exploitcrypto-theftdata breachhealthcare breachiOS vulnerabilitiesinfostealerransomwaresurveillance systems breachtelecom APTvulnerability managementzero-day exploitation
What happened
Multiple high-impact incidents and trends: ransomware group ‘Velvet Tempest’ (Termite) is using the ClickFix social-engineering method with legitimate Windows utilities to deploy DonutLoader and CastleRAT backdoors; a new InstallFix/ClickFix variant and malicious GitHub repos (promoted by AI search prompts) are distributing info-stealers and proxy malware; a critical vulnerability in the widely used WordPress User Registration & Membership plugin is being actively exploited to create admin accounts on ~60k sites; CISA directed federal patching for three iOS flaws exploited by the Coruna kit in
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- cedc9e1b49d7faea8de7117da686c3b630aae0e64bde65dddd9e0b9e48af367e
- Enrichment time
- 2026-03-07T19:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.