Termite has claimed four victims in the past 30 days, with activity concentrated in manufacturing alongside single hits in healthcare, education, and agriculture and food production, and a geographic skew toward the United States alongside isolated claims tied to China, Canada, and Australia. The group is described in open-source reporting as running a modified variant of Babuk ransomware code and claims a history of large-scale data exfiltration, referencing its prior claimed breach of a supply-chain software firm as its signature incident. Recent postings, including a US healthcare provider and a California state agriculture-linked entity, indicate the group continues opportunistic, cross-sector targeting rather than a fixed victim profile. ATT&CK-cataloged techniques associated with Babuk-derived tooling typically include disabling backup and shadow-copy services before file encryption and terminating security processes to evade detection, consistent with what this group claims to employ. Nexus notes these are claims made by the group itself or drawn from third-party leak-site tracking, not independently verified compromise details.