Ransomware
8Base Ransomware Group
Attribution
Financially motivated criminal operation; anonymous throughout its active life. During 2023-2024 only behavioral/code lineage was established (a customized Phobos payload plus a RansomHouse-cloned extortion playbook), leaving competing hypotheses: RansomHouse offshoot, imitator, or an operator reusing leaked Phobos builders. The February 2025 Operation Phobos Aetor arrests of four Russian nationals support a Russia-nexus assessment (medium confidence); individual roles and full organisational structure are not public.
Origin
Unknown (Russia-nexus suspected, based on Feb 2025 arrests)
First seen
2022 (obscure until the mid-2023 surge)
Motivation
Financially motivated (ransomware / double extortion)
Attribution confidence
medium
MENA targeting
Saudi Arabia, Egypt
Sectors
Transportation/aerospace, manufacturing
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Saudi Arabia, Egypt (Transportation/aerospace, manufacturing sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.