8base
- First seen
- 2022-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Last IoC activity
- 2026-07-07 05:18:18
- Profile updated
- 2026-07-07 13:12:13
Targeted industries: manufacturing financial-services technology-and-telecommunications healthcare-and-pharmaceutical
Targeted regions: country_code:us country_code:br country_code:eu
Context
8Base emerged in early 2022 and rapidly escalated its ransomware operations by mid-2023, positioning itself as a “simple pen tester” while executing a relentless double-extortion scheme: encrypting files using AES-256 CBC mode (appending the “.8base” extension) and threatening to leak stolen data via a Tor-accessible leak site. The group leverages initial access methods such as phishing and SmokeLoader, disables security mechanisms like Volume Shadow Copy and firewalls, and deploys persistence via registry and startup entries. Targeting primarily small and medium-sized organizations across sectors such as manufacturing, finance, IT, and healthcare in regions including the U.S., Brazil, and Europe, 8Base has drawn comparisons to Phobos and RansomHouse for its tactics and ransom-note style. In early 2025, international law enforcement operations disrupted the group, resulting in the arrest of four key actors, seizure of servers, and warnings to hundreds of potential victims.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_8Base_Auto (yara-rule)
Reports & references
- blog.sekoia.io — Sekoia Io Mid 2023 Ransomware Threat Landscape (report)
- ransomlook.io — 8Base (report)
- Trend Micro — Ransomware Spotlight 8Base (report)
- sentinelone.com — 8Base (report)
- checkpoint.com — 8Base Ransomware Group (report)
- cyberint.com — All About That 8Base Ransomware Group The Details (report)
- fortinet.com — Ransomware Roundup 8Base (report)
- hhs.gov — 8Base Ransomware Analyst Note (report)
- eye.security — 8Base Ransomware Investigation Uncovers Surprising Insights (report)
- axios.com — Fbi Europol 8Base Ransomware Takedown (report)
- europol.europa.eu — Key Figures Behind Phobos And 8Base Ransomware Arrested In International Cybercrime Crackdown (report)
- Cisco Talos — Talos Ir Q2 2023 Quarterly Recap (report)
- malpedia.caad.fkie.fraunhofer.de — Win.8Base (report)
- npa.go.jp — Ransomdamagerecovery (report)
- Cisco Talos — Deep Dive Into Phobos Ransomware (report)
- acronis.com — 8Base Ransomware Stays Unseen For A Year (report)
- krebsonsecurity.com — Whos Behind The 8Base Ransomware Website (report)
- blog.bushidotoken.net — Unmasking Ransomware Using Stylometric (report)
- twitter.com — 1674718854549831681 (report)
- socradar.io — Dark Web Profile 8Base Ransomware (report)
- logpoint.com — Defending Against 8Base (report)
- trellix.com — Phobos Stealthy Ransomware That Operated Under The Radar Until Now (report)
- circleid.com — 20240530 A Dns Investigation Of The Phobos Ransomware 8Base Attack (report)
- blogs.vmware.com — 8Base Ransomware A Heavy Hitting Player (report)