Back Rescana Aon Ransomware Attack Analysis: Termite Group Exploits CVE-2024
On October 7, 2026, Aon , a leading professional services firm, was publicly reported as the victim of a ransomware attack attributed to the Termite group. The breach was discovered on October 7, 2026, with the initial compromise occurring on October 6, 2026. The incident highlights the persistent threat posed by ransomware actors targeting organizations in the risk management, insurance, and human capital sectors. At the time of writing, no official statement from Aon or law enforcement has been released, and the specific data compromised has not been detailed in public sources. This advisory synthesizes available threat intelligence and technical analysis to inform customers of the attack’s context, technical details, and recommended mitigations.
Technical Information
The attack on Aon is attributed to the Termite ransomware group, which has a documented history of targeting high-value organizations across supply chain, healthcare, and professional services sectors. The group is known for leveraging vulnerabilities in third-party software to gain initial access, followed by rapid lateral movement and data encryption.
Technical analysis from multiple sources indicates that Termite exploited a vulnerability in Cleo file transfer products, specifically LexiCom , VLTransfer , and Harmony . The vulnerability, tracked as CVE-2024-50623 , is an unauthenticated remote code execution (RCE) flaw. Notably, even systems updated to version 5.8.0.21 were reportedly vulnerable, suggesting the group’s exploitation techniques are sophisticated and may bypass existing patches ( Splunk, 2025-05-15 ).
Lateral Movement and Impact
Once inside the network, Termite ransomware enumerates network shares and mapped drives using Windows APIs such as WNetOpenEnum and WNetEnumResourcesW. This enables the malware to identify and encrypt both local and remote resources, maximizing operational disruption. The ransomware also attempts to delete shadow copies using vssadmin.exe, impeding recovery efforts, and stops critical Windows services, particularly those related to security and backup, using the ControlService() API. The malware further leverages SetVolumeMountPoint() to access protected drives and creates ransom notes in multiple formats (.txt, .html, .hta) across affected directories ( Splunk, 2025-05-15 ).
The primary malware identified in this campaign is the Termite ransomware, with a confirmed SHA256 hash of 30a8cf3e6863030c762b468bf48d679f3dd053a80793770443938fa18de89617 ( Splunk, 2025-05-15 ). The group’s toolkit includes standard Windows utilities for system manipulation and defense evasion, such as vssadmin.exe for shadow copy deletion and APIs for service control and drive mounting.
Termite has previously targeted organizations such as Blue Yonder (supply chain), Genea (healthcare, Australia), and entities in consumer products, trucking, shipping, and food services. The group’s attacks often result in significant operational and reputational damage, with documented cases of large-scale data exfiltration and extortion ( Splunk, 2025-05-15 ).
Sector-Specific Implications
As a professional services provider, Aon manages sensitive client data, insurance policy information, and financial records. A ransomware attack on such an organization poses heightened risks of data exposure, regulatory scrutiny, and business disruption. While the specific data compromised in this incident is not detailed in public sources, the sector’s risk profile warrants heightened vigilance.
The observed tactics, techniques, and procedures (TTPs) align with the following MITRE ATT&CK techniques:
Initial Access: Exploit Public-Facing Application (T1190) via CVE-2024-50623 in Cleo software.
Execution: Command and Scripting Interpreter (T1059) using Windows command-line tools.
Defense Evasion: Inhibit System Recovery (T1490) by deleting shadow copies; Impair Defenses (T1562.001) by stopping security and backup services; Service Stop (T1489).
Lateral Movement: Remote Services (T1021) through network enumeration.
Impact: Data Encrypted for Impact (T1486); widespread ransom note creation.
All technical claims are supported by primary sources and mapped to the MITRE ATT&CK framework ( Splunk, 2025-05-15 ).
Affected Versions & Timeline
The attack exploited a vulnerability in Cleo file transfer products, specifically affecting LexiCom , VLTransfer , and Harmony . Systems running version 5.8.0.21 were reportedly still vulnerable as of May 2025, despite vendor patches ( Splunk, 2025-05-15 ).
The verified timeline is as follows: The breach occurred on October 6, 2026. Discovery was made on October 7, 2026. Public disclosure was made via the HookPhish blog on October 7, 2026 ( HookPhish, 2026-10-07 ).
No official regulatory filings or law enforcement advisories have been referenced in public sources as of this writing.
The Termite ransomware group is characterized by its focus on exploiting supply chain and professional services organizations. The group’s modus operandi includes leveraging zero-day or recently patched vulnerabilities in widely used third-party software, followed by rapid lateral movement and aggressive encryption of both local and networked resources. The group is known for deleting system backups and disabling security controls to maximize the impact and leverage for extortion.
In the case of Aon , the attack likely followed this established pattern, with initial access gained via exploitation of Cleo software, followed by network-wide encryption and ransom note deployment. The group’s historical targeting of organizations with large data repositories and critical business operations increases the risk of sensitive data exposure and operational disruption.
Mitigation & Workarounds
Mitigation recommendations are prioritized by severity:
Critical: Organizations using Cleo file transfer products ( LexiCom , VLTransfer , Harmony ) must immediately review their patch status and consult with the vendor regarding the effectiveness of patches for CVE-2024-50623 . Given reports of continued vulnerability in version 5.8.0.21, additional compensating controls such as network segmentation, strict firewall rules, and disabling unnecessary external access to these services are essential ( Splunk, 2025-05-15 ).
High: Implement robust endpoint detection and response (EDR) solutions capable of detecting ransomware behaviors, such as shadow copy deletion and suspicious service stoppage. Monitor for the use of vssadmin.exe, ControlService(), and SetVolumeMountPoint() APIs, as these are commonly abused by ransomware.
High: Conduct regular security awareness training focused on phishing and credential theft, as these remain common initial access vectors for ransomware groups.
Medium: Ensure regular, offline backups of critical data and test restoration procedures. Backups should be isolated from the main network to prevent ransomware propagation.
Medium: Monitor for anomalous network enumeration and access patterns, which may indicate lateral movement by ransomware.
Low: Review and update incident response plans to include ransomware-specific scenarios, ensuring clear communication channels and escalation paths.
Indicators of Compromise
The following indicators are provided for awareness and detection purposes. All indicators are point-in-time and should be validated in your environment before enforcement.
www[.]hookphish[.]com
hxxps://www[.]hookphish[.]com/blog/ransomware-group-termite-hits-aon/
30a8cf3e6863030c762b468bf48d679f3dd053a80793770443938fa18de89617
Rescana provides a Third-Party Risk Management (TPRM) platform designed to help organizations identify, assess, and monitor cyber risks in their vendor ecosystem. Our platform enables continuous monitoring for emerging threats, supports evidence-based risk assessments, and facilitates rapid response to incidents involving supply chain and third-party software vulnerabilities.
We are happy to answer questions at [email protected].
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
