Overview
Platforms:
Windows · Microsoft Windows
Variants:
Phobos (customized version) · Phobos
Extensions:
.8base · .eight
ATT&CK software:
SystemBC · AnyDesk · SmokeLoader · Fast.exe · Netscan
Initial access:
Phishing
Top countries:
US · BR
Observed sectors:
business services · manufacturing · construction · finance · information technology
Tracked victims:
449
Victims
St. Nicholas School
CLAIMED
St. Nicholas School is an international school in Sao Paulo, Brazil, with two campuses: in Pinheiros and Alfaville districts.
Héron
CLAIMED
Héron includes several villages and offers residents a variety of municipal services such as population management, landscaping, transportation, ecology.
Tan Teck Seng Electric (Co) Pte Ltd
CLAIMED
Tan Teck Seng Electric (Co) Pte Ltd, founded in 1973.
High Learn Ltd
CLAIMED
High Learn Ltd is an educational platform based in London, United Kingdom.
Southeast Supply
CLAIMED
Southeast Supply Company provides the easiest, most cost-effective way to supply your students, employees, or fitness center members with convenient.
Show more victims (12)
Cabinet JEAN LOUVEL SAOUDI
CLAIMED
The firm's team consists of experienced lawyers such as Miriam Jean, Stanislas Louvel, Redouane Saudi and Vincent Valentin.
FIO
CLAIMED
FIO (Fourniture Industrielle de l'Ouest) is a French company specializing in providing technical solutions in the fields of automation, hydraulics.
Delta Dental of Washington
CLAIMED
Delta Dental of Washington is one of the leading dental insurance organizations in the United States.
Netform GmbH
CLAIMED
Netform GmbH is a company founded in 2002 specializing in software development.
Wynnewood High School
CLAIMED
Wynnewood High School is part of the Wynnewood Public Schools district in Wynnewood, Oklahoma.
Moraviakov s.r.o.
CLAIMED
Moraviakov s.r.o.
Bring Solution
CLAIMED
Brazil-based Bring Solutions manufactures and sells innovative ingredients, offering customized, fast and reliable solutions to add value to its customers'.
Gebäudereinigungsakademie
CLAIMED
Gebäudereinigungsakademie Gebäudereinigungs akademie in Austria offers professional training in building cleaning, home maintenance and pest control.
HECTARE
CLAIMED
HECTARE, land developer since 1985.
Lake Shore Public Schools
CLAIMED
Lake Shore Public Schools is a school district located in St.
SPORT BOUTIQ
CLAIMED
Sport Boutique is a family business specializing in the sale and rental of ski equipment in Meribel, France, since 1947.
CED Solutions Computer IT Training Centers
CLAIMED
CED Solutions is a company specializing in providing IT training and certifications, including courses on Microsoft, Cisco, CompTIA and other leading technologies.
Operational Activity
Recent Observations
8Base emerges
March 2022
Unit 42 dates the emergence of Squalid Scorpius (8Base) to March 2022.
Use of SmokeLoader for Ransomware Delivery
8base ransomware has been observed being delivered via SmokeLoader variants.
8Base activity surges
June 2023
After a relatively quiet period, 8Base activity increased sharply in June 2023.
TTPs
ATT&CK coverage:
10 techniques
T1486
Data Encrypted for Impact
VERIFIED8Base was reported to encrypt files using AES, with Trend Micro describing AES-256 and RSA-1024 key protection.
T1488
Data Leak
VERIFIEDThe actor maintains a name-and-shame site to publish exfiltrated data from victims who refuse to pay the ransom.
T1135
Network Share Discovery
VERIFIED8Base was reported to use WNetEnumResource() to crawl network resources.
Show more TTPs (7)
T1134.001
Access Token Manipulation: Token Impersonation/Theft
VERIFIEDThe ransomware was reported to use DuplicateToken() to adjust token privileges.
T1562.001
Impair Defenses: Disable or Modify Tools
VERIFIED8Base was reported to terminate security software and other processes.
T1027.002
Obfuscated Files or Information: Software Packing
VERIFIEDSmokeLoader was reported to unpack and load Phobos into memory.
T1490
Inhibit System Recovery
VERIFIEDReported commands delete shadow copies and alter recovery and boot settings.
T1566
Phishing
VERIFIEDTrend Micro reports phishing as the primary initial-access method.
T1071.001
Application Layer Protocol: Web Protocols
VERIFIEDHC3's reproduced VMware mapping associates 8Base command-and-control traffic with web protocols.
T1041
Exfiltration Over C2 Channel
VERIFIEDHC3's reproduced SOCRadar mapping lists exfiltration over the command-and-control channel.
Observed behaviors
Name-and-shame extortion strategy
VERIFIEDName-and-shame extortion behavior documented by the supporting sources.
CVEs
No CVE associations available.
Infrastructure
Data Leak Site (DLS)
A Tor-based website used by the 8Base ransomware group to publish stolen victim data as part of their double-extortion model. The site was seized by international law enforcement in February 2025.
OFFLINE
Last checked:
February 11, 2025
Negotiation Portal
A built-in chat feature within the 8Base darknet site designed to facilitate ransom negotiations between the threat actors and victims. The site was seized by law enforcement in February 2025.
Telegram Channel
Public-facing communication channel used by the group.
Twitter/X Account
Public-facing communication channel used by the group.
Attribution
Roman Berezhnoy
VERIFIED
other
Russian national identified and charged by the U.S. Department of Justice as a leader/operator of the 8Base ransomware affiliate organization.
Egor Nikolaevich Glebov
VERIFIED
other
Russian national identified and charged by the U.S. Department of Justice as a leader/operator of the 8Base ransomware affiliate organization.
Relationships
Phobos
VERIFIED
Reported RaaS relationship
8Base operators deployed modified variants of Phobos ransomware for their extortion campaigns.
Affiliate 2803
VERIFIED
Operator overlap
Reported to be an affiliate platform operated by the same individuals behind 8Base.
Affiliates
Affiliate operation identified. 8Base operated as a Phobos ransomware affiliate organization rather than as the administrator of a public RaaS program.
Timeline
2025-02-11
International law enforcement operation (Operation Phobos Aetor) disrupts 8Base, resulting in the arrest of four suspects in Thailand and seizure of infrastructure.
2023-06
8Base activity increased significantly.
2023-05
Dark Web leak portal went live.
8base ransomware first appeared, according to FortiRecon information.
Show more events (2)
2022-03
8Base group/operation first discovered.
2022
8Base cybercrime syndicate formed.
Sources
A deep dive into Phobos ransomware
Cisco Talos
Ransomware Spotlight: 8Base
Trend Micro
Show more sources (18)
HC3: Analyst Note 8Base Ransomware
U.S. Department of Health and Human Services
Threat Actor Groups Tracked by Palo Alto Networks Unit 42: 8Base (Squalid Scorpius)
Palo Alto Networks Unit 42
Ransomware Roundup: 8base
Fortinet
8Base Ransomware: A Heavy Hitting Player
VMware Carbon Black
Ransomware Roundup: 8base
Fortinet
Threat Actor Groups Tracked by Palo Alto Networks Unit 42
Palo Alto Networks Unit 42
Ransomware Spotlight: 8Base
Trend Micro
Ransomware Gang 8Base has Site Seized by Law Enforcement
Searchlight Cyber
Who's Behind the 8Base Ransomware Website?
Krebs on Security
Phobos Ransomware Affiliates Arrested in Coordinated International Disruption
U.S. Department of Justice
Berezhnoy Glebov Superseding Indictment
U.S. Department of Justice