Financially motivated criminal operation; anonymous throughout its active life. During 2023-2024 only behavioral/code lineage was established (a customized Phobos payload plus a RansomHouse-cloned extortion playbook), leaving competing hypotheses: RansomHouse offshoot, imitator, or an operator reusing leaked Phobos builders. The February 2025 Operation Phobos Aetor arrests of four Russian nationals support a Russia-nexus assessment (medium confidence); individual roles and full organisational structure are not public.
Origin
Unknown (Russia-nexus suspected, based on Feb 2025 arrests)
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
VMware Carbon Black: 8Base terminates security software and common applications before encryption; CISA: affiliates use Process Hacker, PowerTool and Universal Virus Sniffer to kill AV/EDR.
VMware Carbon Black: RansomHouse-style double extortion — stolen data published on the 8Base leak site (ransom note 99% match to RansomHouse) to coerce payment.
VMware Carbon Black and CISA: customized Phobos 2.9.1 AES-encrypts all connected logical drives, appending the .8base extension and branded ransom note.
VMware Carbon Black and CISA: Phobos calls DuplicateToken()/Windows APIs to steal and impersonate access tokens for elevated execution.
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside 8Base's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 9 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialApp GovernanceT1562significantAnti-SpoofingT1566significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1567partialDefender for Cloud AppsT1567.002partialConditional AccessT1110significantConditional AccessT1110.001significantID ProtectionT1110partialID ProtectionT1110.001partialIdentity Secure ScoreT1110partialIdentity Secure ScoreT1110.001partialMultifactor AuthenticationT1110significantMultifactor AuthenticationT1110.001significantMultifactor AuthenticationT1566partialMultifactor AuthenticationT1566.001partialPasswordless AuthenticationT1110significantPasswordless AuthenticationT1110.001significantPassword PolicyT1110partialPassword PolicyT1110.001significantPassword ProtectionT1110partialPassword ProtectionT1110.001partialRole Based Access ControlT1562minimalAntimalwareT1027significantAntimalwareT1566significantAntimalwareT1566.001significantAnti-PhishingT1566significantAnti-PhishingT1566.001significantAntiSpamT1566significantAntiSpamT1566.001significantAudit SolutionsT1562partialInformation ProtectionT1567significant
detect · 13 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001significantApp GovernanceT1110significantApp GovernanceT1110.001significantApp GovernanceT1562significantApp GovernanceT1566significantAdvanced Threat HuntingT1110significantAdvanced Threat HuntingT1110.001significantAdvanced Threat HuntingT1562significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1110partialDefender for Cloud AppsT1110.001partialDefender for Cloud Apps
respond · 7 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.001significantAutomated Investigation and ResponseT1567significantIncident ResponseT1110minimalIncident ResponseT1110.001minimalIncident ResponseT1562minimalIncident ResponseT1566minimalQuarantine PoliciesT1027significantQuarantine PoliciesT1566significantQuarantine PoliciesT1566.001significantSafe AttachmentsT1566significantSafe Attachments
Countermeasures · D3FEND
Defensive techniques that counter 8Base's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.