8Base Ransomware Group
Threat Actor
8Base emerged in March 2022, and their activity spiked in June 2023 after they started attacking companies across a broader range of industry verticals and switching to double extortion. The gang launched its data leak site in May 2023, with the extortion group claiming to be "honest and simple" pen testers targeting "companies that have neglected the privacy and importance of the data of their employees and customers."
As of Jun '23 the ransomware group has listed over 350 victims on its site, announcing up to six victims at once on some days. 8Base uses a customized version of Phobos ransomware, a malware that first surfaced in 2019 and shares many code similarities with Dharma ransomware.
Incidents Associated with this Threat
- December 1, 2024: Ransomware Attack at Port of Rijeka
- October 11, 2024: Volkswagen Seems Unconcerned after Ransomware Attack
- April 22, 2024: Cyberattack at German Gas Warning Systems manufacturer
- April 16, 2024: Email System Temporarily Down at Atlantic States Marine Fisheries Commission
- March 25, 2024: 8Base Leaked Data from German Engineering Company
- February 23, 2024: Production Halted at Glass Plant in Belgium
- January 17, 2024: Ransomware Attack at Nexus Telecom, Switserland
Malware Used by this Threat Actor
No malware identified for this threat actor.
