8Base is a ransomware operation and associated Phobos-derived ransomware strain that became prominent in 2023. It is widely described as a customized version of Phobos used in double-extortion campaigns, combining file encryption with theft of victim data and publication pressure through a dedicated leak site. The operation has been linked to the broader Phobos ecosystem, including reporting that 8Base functioned as a related strain or spinoff and that some Phobos affiliates used 8Base infrastructure to expose stolen data.
8Base primarily targeted small and medium-sized organizations worldwide, with victims spanning sectors including public sector entities, healthcare, education, nonprofits, and other enterprises. Public reporting also associates the group with attacks affecting industrial and manufacturing organizations, and it was repeatedly observed among active ransomware groups impacting Japan and public-sector victims in 2024.
On Windows systems, 8Base has been observed as a PE32 executable written in C/C++ and delivered in at least some intrusions by SmokeLoader. Reported intrusion activity associated with 8Base includes credential dumping, abuse of valid user tokens, privilege escalation via native utilities, and execution of PowerShell. The ransomware establishes persistence through autorun mechanisms, disables recovery options and backup artifacts, impairs host firewall protections, enumerates drives and files, and then encrypts victim data. The analyzed strain used AES-256-CBC for file encryption and protected per-file keys with RSA, behavior consistent with Phobos-family ransomware.
Operationally, 8Base is notable for its use of double extortion. In addition to encrypting files, operators exfiltrated data before encryption and threatened publication on their leak site. Multiple reports indicate that 8Base’s leak infrastructure was also used in connection with Phobos-affiliated activity, reflecting a broader shift in parts of the Phobos ecosystem from primarily encryption-based monetization toward data theft and leak-site extortion.
Law-enforcement actions significantly disrupted the operation. Operation Aether targeted the 8Base group, which authorities believed was linked to Phobos. Public reporting states that infrastructure supporting the leak site was seized, arrests were made in Thailand, and by 2025 the group was widely assessed as dismantled, dormant, or no longer active. Authorities in Japan also released free decryptors for Phobos and 8Base victims.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
S-RM has recently seen data obtained by the Faust team appear on the leak site of 8Base, a ransomware group whose activity began ramping up in mid-2023.
It appears this IP address is hosting the 8Base Ransomware group’s Data Leak Site.
The 8base ransomware group was unveiled in May 2023... 8base primarily targets small and medium-sized companies worldwide in double extortion campaigns.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
First, it copies itself to three different folders on the system... Startup... Next, it creates new Registry keys to enable itself to auto-start: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mtx777 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mtx777
The attackers were also observed dumping credentials from the Local Security Authority Subsystem Service (LSASS) memory, creating new processes with an existing user token to bypass access controls...
The attackers were also observed dumping credentials from the Local Security Authority Subsystem Service (LSASS) memory, creating new processes with an existing user token to bypass access controls...
First, it copies itself to three different folders on the system... Startup... Next, it creates new Registry keys to enable itself to auto-start: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mtx777 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mtx777
The attackers were also observed dumping credentials from the Local Security Authority Subsystem Service (LSASS) memory, creating new processes with an existing user token to bypass access controls...
15 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware group referenced as a law-enforcement target and believed to be linked to Phobos.
Ransomware strain/operation described as a Phobos-related spinoff that increased activity in summer 2023 and claimed multiple high-profile victims.
Ransomware operation (group) targeted by law enforcement; described as linked to Phobos and assembled in 2022.
Related/spinoff ransomware strain associated with the Phobos ecosystem; increased activity noted starting summer 2023 and claimed multiple high-profile victims.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.