8Base Ransomware Group

Threat Actor

8Base emerged in March 2022, and their activity spiked in June 2023 after they started attacking companies across a broader range of industry verticals and switching to double extortion. The gang launched its data leak site in May 2023, with the extortion group claiming to be "honest and simple" pen testers targeting "companies that have neglected the privacy and importance of the data of their employees and customers."

As of Jun '23 the ransomware group has listed over 350 victims on its site, announcing up to six victims at once on some days. 8Base uses a customized version of Phobos ransomware, a malware that first surfaced in 2019 and shares many code similarities with Dharma ransomware.