Overview

Platforms: Windows · Microsoft Windows
Variants: Phobos (customized version) · Phobos
Extensions: .8base · .eight
ATT&CK software: SystemBC · AnyDesk · SmokeLoader · Fast.exe · Netscan
Initial access: Phishing
Top countries: US · BR
Observed sectors: business services · manufacturing · construction · finance · information technology
Tracked victims: 449

Victims

St. Nicholas School CLAIMED
February 1, 2025 BR Schools 3 tracker sources
St. Nicholas School is an international school in Sao Paulo, Brazil, with two campuses: in Pinheiros and Alfaville districts.
Héron CLAIMED
February 1, 2025 BE Unknown 3 tracker sources
Héron includes several villages and offers residents a variety of municipal services such as population management, landscaping, transportation, ecology.
Tan Teck Seng Electric (Co) Pte Ltd CLAIMED
February 1, 2025 SG Technology 3 tracker sources
Tan Teck Seng Electric (Co) Pte Ltd, founded in 1973.
High Learn Ltd CLAIMED
February 1, 2025 GB Education 3 tracker sources
High Learn Ltd is an educational platform based in London, United Kingdom.
Southeast Supply CLAIMED
January 31, 2025 US Retail & E-Commerce 3 tracker sources
Southeast Supply Company provides the easiest, most cost-effective way to supply your students, employees, or fitness center members with convenient.
Show more victims (12)
Cabinet JEAN LOUVEL SAOUDI CLAIMED
January 24, 2025 FR Legal Services 3 tracker sources
The firm's team consists of experienced lawyers such as Miriam Jean, Stanislas Louvel, Redouane Saudi and Vincent Valentin.
FIO CLAIMED
January 23, 2025 FR Unknown 3 tracker sources
FIO (Fourniture Industrielle de l'Ouest) is a French company specializing in providing technical solutions in the fields of automation, hydraulics.
Delta Dental of Washington CLAIMED
January 16, 2025 US Insurance services 3 tracker sources
Delta Dental of Washington is one of the leading dental insurance organizations in the United States.
Netform GmbH CLAIMED
January 16, 2025 DE Manufacturing 3 tracker sources
Netform GmbH is a company founded in 2002 specializing in software development.
Wynnewood High School CLAIMED
January 14, 2025 US Universities 3 tracker sources
Wynnewood High School is part of the Wynnewood Public Schools district in Wynnewood, Oklahoma.
Moraviakov s.r.o. CLAIMED
January 14, 2025 CZ Manufacturing 3 tracker sources
Moraviakov s.r.o.
Bring Solution CLAIMED
January 14, 2025 BR Unknown 3 tracker sources
Brazil-based Bring Solutions manufactures and sells innovative ingredients, offering customized, fast and reliable solutions to add value to its customers'.
Gebäudereinigungsakademie CLAIMED
January 14, 2025 AT Business Services 3 tracker sources
Gebäudereinigungsakademie Gebäudereinigungs akademie in Austria offers professional training in building cleaning, home maintenance and pest control.
HECTARE CLAIMED
January 7, 2025 FR Technology 3 tracker sources
HECTARE, land developer since 1985.
Lake Shore Public Schools CLAIMED
January 7, 2025 US Schools 3 tracker sources
Lake Shore Public Schools is a school district located in St.
SPORT BOUTIQ CLAIMED
January 7, 2025 FR Shops 3 tracker sources
Sport Boutique is a family business specializing in the sale and rental of ski equipment in Meribel, France, since 1947.
CED Solutions Computer IT Training Centers CLAIMED
January 7, 2025 US Information Technologies Consulting 3 tracker sources
CED Solutions is a company specializing in providing IT training and certifications, including courses on Microsoft, Cisco, CompTIA and other leading technologies.

Operational Activity

Recent Observations

8Base emerges
March 2022
Unit 42 dates the emergence of Squalid Scorpius (8Base) to March 2022.
Use of SmokeLoader for Ransomware Delivery
8base ransomware has been observed being delivered via SmokeLoader variants.
8Base activity surges
June 2023
After a relatively quiet period, 8Base activity increased sharply in June 2023.

TTPs

ATT&CK coverage: 10 techniques
T1486 Data Encrypted for Impact
VERIFIED
8Base was reported to encrypt files using AES, with Trend Micro describing AES-256 and RSA-1024 key protection.
T1488 Data Leak
VERIFIED
The actor maintains a name-and-shame site to publish exfiltrated data from victims who refuse to pay the ransom.
T1135 Network Share Discovery
VERIFIED
8Base was reported to use WNetEnumResource() to crawl network resources.
Show more TTPs (7)
T1134.001 Access Token Manipulation: Token Impersonation/Theft
VERIFIED
The ransomware was reported to use DuplicateToken() to adjust token privileges.
T1562.001 Impair Defenses: Disable or Modify Tools
VERIFIED
8Base was reported to terminate security software and other processes.
T1027.002 Obfuscated Files or Information: Software Packing
VERIFIED
SmokeLoader was reported to unpack and load Phobos into memory.
T1490 Inhibit System Recovery
VERIFIED
Reported commands delete shadow copies and alter recovery and boot settings.
T1566 Phishing
VERIFIED
Trend Micro reports phishing as the primary initial-access method.
T1071.001 Application Layer Protocol: Web Protocols
VERIFIED
HC3's reproduced VMware mapping associates 8Base command-and-control traffic with web protocols.
T1041 Exfiltration Over C2 Channel
VERIFIED
HC3's reproduced SOCRadar mapping lists exfiltration over the command-and-control channel.

Observed behaviors

Name-and-shame extortion strategy
VERIFIED
Name-and-shame extortion behavior documented by the supporting sources.

CVEs

No CVE associations available.

Infrastructure

Data Leak Site (DLS)
A Tor-based website used by the 8Base ransomware group to publish stolen victim data as part of their double-extortion model. The site was seized by international law enforcement in February 2025.
OFFLINE
Last checked: February 11, 2025
Negotiation Portal
A built-in chat feature within the 8Base darknet site designed to facilitate ransom negotiations between the threat actors and victims. The site was seized by law enforcement in February 2025.
Telegram Channel
Public-facing communication channel used by the group.
Twitter/X Account
Public-facing communication channel used by the group.

Attribution

Roman Berezhnoy VERIFIED
other
Russian national identified and charged by the U.S. Department of Justice as a leader/operator of the 8Base ransomware affiliate organization.
Egor Nikolaevich Glebov VERIFIED
other
Russian national identified and charged by the U.S. Department of Justice as a leader/operator of the 8Base ransomware affiliate organization.

Relationships

Phobos VERIFIED
Reported RaaS relationship
8Base operators deployed modified variants of Phobos ransomware for their extortion campaigns.
Affiliate 2803 VERIFIED
Operator overlap
Reported to be an affiliate platform operated by the same individuals behind 8Base.

Affiliates

Affiliate operation identified. 8Base operated as a Phobos ransomware affiliate organization rather than as the administrator of a public RaaS program.

Timeline

2025-02-11
International law enforcement operation (Operation Phobos Aetor) disrupts 8Base, resulting in the arrest of four suspects in Thailand and seizure of infrastructure.
2023-06
8Base activity increased significantly.
2023-05
Dark Web leak portal went live.
8base ransomware first appeared, according to FortiRecon information.
Show more events (2)
2022-03
8Base group/operation first discovered.
2022
8Base cybercrime syndicate formed.

Sources