Skip to content

8Base

8Base is a ransomware operation and associated Phobos-derived ransomware strain that became prominent in 2023.

Profile source: Mallory opens in a new tab

8Base

Family profile

8Base is a ransomware operation and associated Phobos-derived ransomware strain that became prominent in 2023. It is widely described as a customized version of Phobos used in double-extortion campaigns, combining file encryption with theft of victim data and publication pressure through a dedicated leak site. The operation has been linked to the broader Phobos ecosystem, including reporting that 8Base functioned as a related strain or spinoff and that some Phobos affiliates used 8Base infrastructure to expose stolen data.

8Base primarily targeted small and medium-sized organizations worldwide, with victims spanning sectors including public sector entities, healthcare, education, nonprofits, and other enterprises. Public reporting also associates the group with attacks affecting industrial and manufacturing organizations, and it was repeatedly observed among active ransomware groups impacting Japan and public-sector victims in 2024.

On Windows systems, 8Base has been observed as a PE32 executable written in C/C++ and delivered in at least some intrusions by SmokeLoader. Reported intrusion activity associated with 8Base includes credential dumping, abuse of valid user tokens, privilege escalation via native utilities, and execution of PowerShell. The ransomware establishes persistence through autorun mechanisms, disables recovery options and backup artifacts, impairs host firewall protections, enumerates drives and files, and then encrypts victim data. The analyzed strain used AES-256-CBC for file encryption and protected per-file keys with RSA, behavior consistent with Phobos-family ransomware.

Operationally, 8Base is notable for its use of double extortion. In addition to encrypting files, operators exfiltrated data before encryption and threatened publication on their leak site. Multiple reports indicate that 8Base’s leak infrastructure was also used in connection with Phobos-affiliated activity, reflecting a broader shift in parts of the Phobos ecosystem from primarily encryption-based monetization toward data theft and leak-site extortion.

Law-enforcement actions significantly disrupted the operation. Operation Aether targeted the 8Base group, which authorities believed was linked to Phobos. Public reporting states that infrastructure supporting the leak site was seized, arrests were made in Thailand, and by 2025 the group was widely assessed as dismantled, dormant, or no longer active. Authorities in Japan also released free decryptors for Phobos and 8Base victims.

Capabilities

  • Credential Theft
  • Defense Evasion
  • Exfiltration
  • Extortion
  • Persistence
  • Privilege Escalation

Operational record

1
YARA rules
3
Ransom notes
4
Leak sites
0 available

Credential Theft

  • LaZagne
  • Mimikatz
  • NirSoft VNCPassView
  • NirSoft WebBrowserPassView
  • PasswordFox
  • ProcDump

Defense Evasion

  • GMER
  • PCHunter
  • ProcessHacker

Exfiltration

  • RClone

LOLBAS

  • PsExec

Reported operators

Threat actors

3 named in public reporting
Faust

S-RM has recently seen data obtained by the Faust team appear on the leak site of 8Base, a ransomware group whose activity began ramping up in mid-2023.

ShadowSyndicate

It appears this IP address is hosting the 8Base Ransomware group’s Data Leak Site.

RansomHouse

The 8base ransomware group was unveiled in May 2023... 8base primarily targets small and medium-sized companies worldwide in double extortion campaigns.

MITRE ATT&CK

8Base in ATT&CK

36 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.