Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareRansomwareUsed by 2 actors

8Base

8Base is a ransomware operation and related ransomware strain commonly referred to as 8Base. The content describes it as a Ransomware-as-a-Service/spinoff operation linked to Phobos, with multiple sources stating that 8Base used a variant of Phobos or launched on leaked Phobos code. It emerged in 2022 and gained prominence in 2023, ramping up activity in the summer of 2023. The group primarily targeted small and medium-sized organizations worldwide and conducted double-extortion campaigns, stealing data and threatening publication on its data leak site. Reported victims and claimed targets mentioned in the content include public-sector entities, manufacturing and healthcare organizations, the United Nations Development Programme, the Atlantic States Marine Fisheries Commission, a Canadian agency administering dental benefit plans for disabled people in Alberta, and Volkswagen Group.

Technically, the ransomware is described as encrypting files with AES-256 in CBC mode and protecting per-drive or per-share AES keys with RSA. For files larger than 1.5 MB, it encrypts three 256 KB chunks at the beginning, middle, and end of the file. It appends the .8base extension to encrypted files, adds encrypted metadata and a plaintext footer, deletes Volume Shadow Copies, and disables recovery mode to hinder restoration. The content notes that encryption keys are zeroed from memory immediately after use, complicating key recovery. Initial access is reported to occur via phishing emails or initial access brokers.

The operation maintained a dark-web data leak site and used channels including Twitter and Telegram. One cited indicator is IP address 92.118.36.204, reported as hosting the 8Base data leak site. The group was repeatedly assessed as linked to Phobos, and law-enforcement reporting tied PHOBOS/8Base operators to more than 1,000 victims worldwide and over $16 million in ransom proceeds since 2019. Europol's Operation Aether targeted 8Base; reporting in the content states that infrastructure was disrupted, more than 100 servers tied to the broader scheme were taken down, arrests were made including in Thailand, and Bavarian police seized infrastructure hosting the 8Base leak site. Several sources state the group ceased or largely ceased operations following law-enforcement action in February 2025. The content also notes that authorities released free decryptors for Phobos and 8Base victims, including guidance published by Japan's National Police Agency.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
ShadowSyndicate

It appears this IP address is hosting the 8Base Ransomware group’s Data Leak Site.

via osint team blogosintteam.blog
RansomHouse

The 8base ransomware group was unveiled in May 2023... 8base primarily targets small and medium-sized companies worldwide in double extortion campaigns.

via sekoia blogblog.sekoia.io
MITRE ATT&CK

Techniques & procedures

1 distinct technique documented for this family, organized by ATT&CK tactic.

Impact

1 technique
T1486Data Encrypted for ImpactEvidence3

"...operators and affiliates who conducted the attacks and encrypted victim systems."

INDICATORS OF COMPROMISE

IOCs tracked for this family

12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
4 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
5 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
3 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app4 days ago
domain●●●●●●●●●●●●View more in app4 days ago
hash.sha256●●●●●●●●●●●●View more in app4 days ago
hash.sha256●●●●●●●●●●●●View more in app4 days ago
domain●●●●●●●●●●●●View more in app4 days ago
hash.sha256●●●●●●●●●●●●View more in app4 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching12

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping1

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.