8Base
Aliases: 8Base ransomware
Source profile review date: 2026-06-01
Added to the source registry: 2023-05-23 · Source snapshot: 2026-09-15
Source metadata is not independently verified. The registry date is not necessarily the first attack date. Source synopses are translated automatically where needed; the feed may contain outdated assessments.
Research status: Existing researched dossier
This dossier separates actor-specific source information from general defensive analysis. Recommendations and investigation questions are not additional claims about the actor. Public evidence remains limited where explicitly stated.
Executive summary
8Base is a double-extortion group with strong activity since 2023, often discussed in relation to Phobos-like ransomware and RansomHouse-like communication.
8Base uses name-and-shame pressure, opportunistic victims and artefacts such as the .8base extension. VMware described similarities with Phobos and a strong activity spike in 2023.
Latest five known victim claims
Loading stored claims…
These are public claims attributed to the group, not independently confirmed breaches. Dates indicate publication or discovery, not necessarily the attack date.
Executive summary
8Base is relevant because the group shows a recognisable ransomware or extortion chain: opportunistic double extortion with name-and-shame publication and Phobos-like technical characteristics. For visitors this is not just a name to remember, but a scenario to test their own environment against.
The most important question is where the organisation is vulnerable before encryption becomes visible. With 8Base, the defensible phase is mainly initial access, lateral movement, data discovery, staging, exfiltration and abuse of administrative rights.
The profile is written as a practical CTI dossier: what the group does, which artefacts are known, which victims or sectors recur and which measures reduce the chance that the same method succeeds.
Group and development
8Base should be managed as a living profile. Actors change tooling, affiliates, leak sites and negotiators, but operational patterns often remain recognisable.
According to VMware, victims included business services, finance, manufacturing and IT. That pattern points to opportunistic selection based on access and extortion value.
When a group becomes older or less active, the dossier remains useful as a case profile as long as the attack techniques return with new groups. Therefore we remove only real noise profiles, not historically useful groups.
Attack pattern from public cases
VMware described 8Base as active since March 2022, with a strong spike in June 2023. The group targeted varied sectors and used public leak-site communication to build pressure.
Known artefacts include the .8base extension, Phobos-like characteristics, network share discovery via WNetEnumResource and persistence via Startup folders or Run Keys.
Damage usually develops in phases. First access is made usable, then the environment is understood, then data is collected or administrative reach is expanded, and only after that encryption, publication or further extortion follows.
Known IOCs and artefacts
Use hard IOCs mainly for retro-hunting and confirmation. The structural detection value is in behaviour: remote access, tool use, data staging, privilege changes, service stops and unusual file activity.
Known artefacts include the .8base extension, Phobos-like characteristics, network share discovery via WNetEnumResource and persistence via Startup folders or Run Keys.
Record per incident which files, notes, extensions, command lines, external destinations and accounts were actually observed. This prevents old indicators from being treated as current truth.
Practical detection logic
Connect identity to endpoint behaviour. A suspicious login becomes truly relevant when it is followed by discovery, remote execution, tool installation, file-share access or data staging.
Monitor sensitive data for mass access, archiving and outbound transfer. In double extortion this is often more important than the first encryption alert.
Check administrative platforms, RDP, PowerShell, PsExec-like behaviour, RMM tools and hypervisor or backup consoles for abnormal use. Ransomware often uses ordinary administration paths.
Concrete hardening priorities
Limit broad SMB share access, monitor startup persistence and detect rapid file changes on file shares. Make sensitive data and outbound transfer visible before publication pressure arises.
Enforce MFA on external access, restrict RDP and VPN, segment servers and protect backups outside the normal domain administration layer.
Ensure central logging for identity, VPN, EDR, firewall, Windows Event Logs, cloud storage and backup platforms. Local logs alone are insufficient during ransomware.
Identity, naming and attribution
For 8Base, the operational starting point is an exact identity match. The local dossier records the following names or aliases: 8Base ransomware. An alias is a search aid, not independent evidence of shared operators. Similar names, reused logos and the same extortion vocabulary cannot establish a relationship between groups. Analysts should retain the original spelling of a claim and distinguish the publisher, malware family and suspected intrusion operator. Those roles can belong to different people. This prevents an incident being assigned to the wrong group simply because a filename or public post resembles an earlier case. Any proposed relationship needs its own dated, attributable source.
Timeline and interpretation of dates
The source registry date available for 8Base is 2023-05-23; the metadata snapshot was collected on 2026-09-15. These timestamps describe the available record, not a proven beginning of criminal operations. Registration may follow earlier activity, and a claim can concern an older incident. A defensible timeline separates suspected intrusion, data access, discovery by the victim, publication by the claimant and discovery by the monitoring service. The profile review date is another independent timestamp. Analysts should not silently convert one date into another. When sources disagree, preserve both observations and their provenance, then explain the uncertainty rather than presenting a falsely precise attack chronology.
Victim claims and targeting assessment
The victim panel for 8Base shows up to five distinct organisations from the stored claim history. It is a moving observation window, not a complete incident census. Public listings can omit victims, repeat old material or exaggerate access. Consequently, a short run of organisations in one country or industry does not by itself prove deliberate targeting of that sector. The useful comparison is with the organisation's own dependencies: shared providers, remote access arrangements, exposed services and sensitive data flows. A supplier appearing in a claim justifies verification through established contacts, but does not establish that downstream customers were compromised. Separate confirmed statements from the claimant's assertions.
Indicators of compromise (IOCs)
Indicators are historical observations, not proof of a current infection. Validate source, age and context before hunting or blocking; legitimate administrative tools can produce false positives.
| Type | Value | Source | Context |
|---|---|---|---|
| extension | .8base | VMware Carbon Black 2023 | Observed encrypted file extension. |
| behavior | WNetEnumResource network share discovery | VMware Carbon Black 2023 | Network resource crawling. |
| persistence | Startup Folder / Run Keys | VMware Carbon Black 2023 | Persistence paths described by VMware. |
Sources
- VMware: 8Base Ransomware: A Heavy Hitting Player
- MITRE ATT&CK — Valid Accounts (defensive context)
- MITRE ATT&CK — External Remote Services (defensive context)
- MITRE ATT&CK — Exfiltration Over Web Service (defensive context)
- MITRE ATT&CK — Inhibit System Recovery (defensive context)
- Ransomware.live — 8Base
Evidence and limitations
Attribution describes the source assessment, not a verified identity. A leak-site listing alone does not prove encryption, data theft, a particular vulnerability or an affiliate relationship. Missing information is left explicit.