8base Ransomware

Description Summary

8base emerged publicly in March 2022 but stayed relatively quiet until a surge of activity in mid-2023 made it one of the most active leak-site operators of that period. Researchers determined that 8base uses a Phobos-based encryptor and overlaps significantly with the RansomHouse cartel in terms of leak-site copy and ransom-note language.

Threat Actor

Phobos affiliate cluster operating their own leak site. Targets have been predominantly small and mid-sized businesses.

Technical Indicators

Encryption Extension
.8base / .id[<ID>].[<email>].8base
Encryption Algorithm
AES-256 + RSA (Phobos engine)
Ransom Note Name
info.txt / README.html
Targeted Industries
Business services, Manufacturing, Construction, Finance
First Seen
March 2022
Last Seen
March 2022 – February 2025 — DISMANTLED (Operation Phobos Aetor)
Geographical Location
United States, Brazil, United Kingdom, Australia

MITRE ATT&CK Matrix

Tactic TTP Technique Name
Initial Access x 3 T1566 Phishing
T1190 Exploit Public-Facing Application
T1078 Valid Accounts
Execution x 1 T1059 Command and Scripting Interpreter
Execution Persistence x 1 T1053 Scheduled Task/Job
Defense Evasion x 2 T1562.001 Disable or Modify Tools
T1070.004 File Deletion
Discovery x 2 T1083 File and Directory Discovery
T1082 System Information Discovery
Lateral Movement x 2 T1021.001 Remote Services: RDP
T1021.002 SMB/Windows Admin Shares
Exfiltration x 2 T1041 Exfiltration Over C2 Channel
T1567.002 Exfiltration to Cloud Storage
Impact x 3 T1486 Data Encrypted for Impact
T1490 Inhibit System Recovery
T1489 Service Stop