8Base is a Windows ransomware family and associated cybercriminal extortion operation that uses a customized version of Phobos ransomware. Its associated data leak site appeared in March 2022, and activity increased substantially in mid-2023. The operation primarily targets small and medium-sized organizations worldwide, with victims also including public-sector entities and industrial organizations. Attacks follow a double-extortion model, combining data theft before encryption with threats to publish stolen information on a Tor-hosted leak site. Faust operators within the Phobos ecosystem have also used the 8Base leak site to publish stolen victim data.
8Base has been delivered through SmokeLoader. An analyzed encryptor is a 32-bit Windows executable written in C/C++ that decrypts executable code and dynamically reconstructs imports at runtime. It establishes persistence through startup locations and registry autorun entries, enumerates drives and files, and encrypts files using AES-256-CBC. A randomly generated initialization vector and an RSA-encrypted AES key are appended to encrypted files. The malware avoids the Windows system directory and files already encrypted by itself, then leaves ransom notes. It inhibits recovery by deleting volume shadow copies and backup catalogs and disabling Windows recovery settings. It also disables the Windows firewall.
Observed 8Base intrusions have included AnyDesk deployment, LSASS credential dumping, execution using an existing user token, privilege escalation, and PowerShell execution. These are operator behaviors accompanying ransomware deployment rather than necessarily functions of the encryptor itself.
International law enforcement disrupted the operation in February 2025 through Operation Aether, including arrests in Thailand and seizure of leak-site infrastructure. Japan’s National Police Agency subsequently released a free decryptor for Phobos and 8Base victims with support from the FBI and Europol.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
S-RM has recently seen data obtained by the Faust team appear on the leak site of 8Base, a ransomware group whose activity began ramping up in mid-2023.
It appears this IP address is hosting the 8Base Ransomware group’s Data Leak Site.
The 8base ransomware group was unveiled in May 2023... 8base primarily targets small and medium-sized companies worldwide in double extortion campaigns.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
First, it copies itself to three different folders on the system... Startup... Next, it creates new Registry keys to enable itself to auto-start: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mtx777 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mtx777
The attackers were also observed dumping credentials from the Local Security Authority Subsystem Service (LSASS) memory, creating new processes with an existing user token to bypass access controls...
The attackers were also observed dumping credentials from the Local Security Authority Subsystem Service (LSASS) memory, creating new processes with an existing user token to bypass access controls...
First, it copies itself to three different folders on the system... Startup... Next, it creates new Registry keys to enable itself to auto-start: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mtx777 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mtx777
The attackers were also observed dumping credentials from the Local Security Authority Subsystem Service (LSASS) memory, creating new processes with an existing user token to bypass access controls...
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware family covered by a law-enforcement-published decryptor for supported variants.
Ransomware group referenced as a law-enforcement target and believed to be linked to Phobos.
Ransomware strain/operation described as a Phobos-related spinoff that increased activity in summer 2023 and claimed multiple high-profile victims.
Ransomware operation (group) targeted by law enforcement; described as linked to Phobos and assembled in 2022.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.