8Base — Ransomware Profile
8Base is a ransomware group that emerged prominently in 2023 targeting SMBs globally with a Phobos-based ransomware and an aggressive leak site.Also tracked as
Eight ransomware (Phobos variant), 8base, .8base
Tools & malware
- defoff.bat defense evasion script
- LaZagne credential theft
- Mimikatz credential theft
- Phobos ransomware
- ProcDump credential theft
- PsExec lateral movement
- RClone exfiltration
- SmokeLoader loader
- SystemBC RAT/proxy
Recent claimed victims
- High Learn Ltd 2025-02-01
- St. Nicholas School 2025-02-01
- Tan Teck Seng Electric (Co) Pte Ltd 2025-02-01
- Héron 2025-02-01
- Southeast Supply 2025-01-31
- Cabinet JEAN LOUVEL SAOUDI 2025-01-24
- FIO 2025-01-23
- Delta Dental of Washington 2025-01-16
- Netform GmbH 2025-01-16
- Gebäudereinigungsakademie 2025-01-14
- Bring Solution 2025-01-14
- Wynnewood High School 2025-01-14
- Moraviakov s.r.o. 2025-01-14
- Bergström Wines 2025-01-07
- CED Solutions Computer IT Training Centers 2025-01-07
- Omnitravel 2025-01-07
- Lake Shore Public Schools 2025-01-07
- SPORT BOUTIQ 2025-01-07
- Weininger Metall System GmbH 2025-01-07
- IRO PARIS 2025-01-07
- ASCOM S.p.A. 2025-01-07
- HECTARE 2025-01-07
- SolGeo AG Baugelogie and Geotechnik 2025-01-03
- Grupo Buddemeyer 2025-01-03
- Jay Enn Corporation 2025-01-03
Vendor research
- 8Base Ransomware: A Heavy Hitting Player VMware Carbon Black
- Ransomware Spotlight: 8Base Trend Micro
- #StopRansomware: Phobos Ransomware (AA24-060A) CISA
- Key figures behind Phobos and 8Base ransomware arrested in international cybercrime crackdown Europol
- Police arrests 2 Phobos ransomware suspects, seizes 8Base sites BleepingComputer