Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
8Base was a financially motivated ransomware operation that surged to prominence in mid-2023 and ranked among the most active extortion brands of 2023-2024, running a double-extortion model via a Tor-based data-leak-and-negotiation site. Technically it was not an original developer: it deployed a customized Phobos variant (delivered via SmokeLoader) while cloning the RansomHouse extortion playbook and leak-site branding. Its infrastructure was seized and its operators arrested in the February 2025 international law-enforcement action Operation Phobos Aetor, and it is now effectively defunct.
8Base-branded samples and leak-site victims first appear around 2022 (VMware Carbon Black dates the group's first appearance to March 2022), but the operation ran at low volume and drew little attention for roughly a year - which is why many secondary reports mistakenly cite its mid-2023 surge as its 'emergence'.
In May-June 2023 its posting volume exploded: it listed on the order of 130+ organizations in about three months and briefly ranked among the two most active ransomware brands by victim postings, prompting VMware to label it a 'heavy hitter'. The group publicly styled itself as 'simple pen testers' and maintained Telegram and Twitter contact channels.
Two independent lineage threads define 8Base. The malware is a customized Phobos ransomware v2.9.1, unpacked and loaded via SmokeLoader and re-branded by appending the '.8base' extension and lightly editing the Phobos ransom-note template - tying it into the Phobos ransomware-as-a-service ecosystem covered by CISA/FBI advisory AA24-060A. The extortion playbook is near-identical to RansomHouse: VMware's linguistic analysis found 8Base's ransom notes a ~99% match to RansomHouse notes and its leak-site copy copied near word-for-word, leading researchers to assess 8Base as a RansomHouse offshoot, imitator, or an operator reusing leaked builders. This lineage question remains unresolved.
Operationally the group leaned on commodity tooling and opportunistic, high-volume targeting of small-to-mid businesses (professional services, manufacturing, healthcare, finance, retail, technology): initial access via phishing and exposed or brute-forced RDP, SmokeLoader for staging, disabling security tooling and deleting Volume Shadow Copies to inhibit recovery, and token impersonation for privilege escalation.
In February 2025, Operation Phobos Aetor - coordinated by Europol with the FBI, UK NCA and agencies across Europe and Asia - seized 8Base's data-leak and negotiation sites, dismantled 100+ servers, and arrested four Russian nationals; U.S. authorities separately charged Roman Berezhnoy and Egor Glebov. Authorities attributed 1,000+ victims globally and roughly $16M in proceeds to the associated Phobos/8Base activity. Its infrastructure has remained offline since, with the last observed victim on 2025-02-01; 8Base should be treated as defunct/dormant, while noting that its personnel and Phobos tooling could resurface under new branding.
+16 more relationships — see the relationships browser.
MENA relevance: 8Base's documented victimology is overwhelmingly US, Western European (France, Italy, Germany) and Brazilian small-to-mid businesses. Its RaqibCTI Saudi Arabia and Egypt country tags rest on a single UNVERIFIED leak-site listing (Saudia MRO / Saudia Technic, listed 2024-02-28) and one uncorroborated Egyptian mention respectively - neither is a confirmed compromise. 8Base should not be read as a MENA-focused actor.