Home/Threat Actor/8Base
Threat Actor

8Base

base_8 · russia_speaking_cybercrime · active since 2022-03

8Base (canonical industry naming per VMware Carbon Black + Cisco Talos + Bleeping Computer + SecurityAffairs + Avertium tracking) is a Phobos v2.9.1 customized variant ransomware operator active since March 2022 with signature SmokeLoader embedded-payload delivery + cluster-defining suspected RansomHouse rebrand operator-relation per VMware Carbon Black June 2023 analysis (99% Doc2Vec ransom note match + identical FAQ + identical Terms of Service)

Russia-based organized cybercrime attribution via Cisco Talos (Guilherme Venere) canonical November 2023 two-part Phobos variant analysis ("8Base utilizes a modified version of the Phobos v2.9.1 ransomware, which is distributed via SmokeLoader. Phobos, an Ransomware-as-a-Service RaaS operation that emerged in 2019, shares code similarities with the Dharma ransomware") + U.S. DOJ February 2025 charges against Russian nationals Roman Berezhnoy + Egor Glebov for operating Phobos ransomware group ("They allegedly targeted over 1,000 public and private entities worldwide, extorting more than $16 million in ransom") + Europol + FBI + NoMoreRansom November 2024+ free decryptor release.

standalone cluster paralleling bianlian + inc_ransom + noescape in v0.1.148 post- Conti-takedown 2022-2024 RaaS fragmentation operators cell.

operational target profile U.S. + Brazil primary geographic targets per VMware June 2023 + SMBs primary target size + finance + manufacturing + business services + IT primary sectors with 67 victims by May 2023 + 107+ by July 2023.

operational attack architecture: (1) cluster-defining Phobos v2.9.1 customized ransomware variant with Dharma/Crysis 2019+ RaaS family code lineage per Cisco Talos + VMware.

(2) cluster-defining SmokeLoader embedded-payload delivery per Cisco Talos November 2023 ("This commodity loader typically drops or downloads additional payloads when deployed. In 8Base campaigns, however, it has the ransomware component embedded in its encrypted payloads, which is then decrypted and loaded into the SmokeLoader process' memory"), unique cluster-defining delivery distinguishing 8Base from typical SmokeLoader external-download-of- payload pattern.

(3) cluster-defining suspected RansomHouse rebrand operator-relation signature per VMware Carbon Black + ISH Tecnologia ("The first similarity noticed would be the comparison of the ransom note using the Doc2Vec neural language processing model. During the analysis, the 8base ransom note had a 99% match with the RansomHouse ransom note. In addition, the blog used by both groups of ransomware appear to be identical"); (4) cluster-defining "honest and simple pentesters" leak site branding distinctive among ransomware operators ("We are honest and simple pentesters. We offer companies the most loyal conditions for the return of their data")

(5) signature .8base + .eight + .elbie + .faust + .LIZARD file extensions Phobos variant lineage + helpermail@onionmail.org contact email consistent since June 2022 per Bleeping Computer.

(6) admlogs25.xyz payload domain + SystemBC proxy malware C2 obfuscation association signature per VMware.

(7) "cartilage" ransom note top corner branding + purple background HTA distinctive ransom note tradecraft.

(8) double- extortion encryption + data leak threat tradecraft; (9) cluster-defining February 2025 U.S. DOJ Berezhnoy + Glebov Phobos operators arrests ($16M+ extortion + 1000+ entities targeted + coordinated international operation infrastructure dismantling)

(10) cluster-defining Europol + FBI + NoMoreRansom decryptor November 2024+ release defeating 8Base encryption capability for affected victims.

cluster fills the March-2022-onward + Phobos-v2.9.1-variant + SmokeLoader-embedded-payload + RansomHouse-rebrand-suspected + "honest pentesters" branding + DOJ Phobos arrests position in post- Conti-takedown 2022-2024 RaaS fragmentation operators cell.

canonical illustration of Phobos variant operator + SmokeLoader embedded delivery + RansomHouse operator-relation + distinctive branding + Phobos operator law enforcement disruption + decryptor release cited in essentially all subsequent ransomware industry analyses through 2022-2026 period.

russia_speaking_cybercrime confidence: high 19 aliases

Profile

8Base (canonical industry naming per multiple tracking including VMware Carbon Black + Cisco Talos + Bleeping Computer + SecurityAffairs + Avertium) is a Phobos v2.9.1 customized variant ransomware operator active since March 2022 with signature SmokeLoader embedded-payload delivery + suspected RansomHouse rebrand operator-relation. Russia-based organized cybercrime attribution via VMware Carbon Black June 2023 RansomHouse-rebrand- suspected analysis + Cisco Talos canonical Phobos v2.9.1 variant identification + U.S. DOJ February 2025 Berezhnoy + Glebov Phobos arrests + Europol + FBI + NoMoreRansom November 2024+ decryptor.

Standalone cluster paralleling bianlian + inc_ransom + noescape in v0.1.148 post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.

Operational target profile
  • U.S. + Brazil primary geographic targets per VMware June 2023.
  • SMBs primary target size per VMware.
  • Finance + manufacturing + business services + IT primary sectors per VMware.
  • 67 victims by May 2023, 107+ by July 2023 Operational attack architecture: (1) Phobos v2.9.1 customized ransomware variant (cluster-defining): per Cisco Talos + VMware, Phobos lineage from Dharma/Crysis 2019+ RaaS family (2) SmokeLoader embedded-payload delivery (cluster- defining): per Cisco Talos November 2023, unique delivery distinguishing 8Base from typical SmokeLoader pattern ("In 8Base campaigns, however, it has the ransomware component embedded in its encrypted payloads, which is then decrypted and loaded into the SmokeLoader process' memory") (3) Suspected RansomHouse rebrand (cluster- defining): per VMware Carbon Black + ISH Tecnologia, 99% Doc2Vec ransom note match + identical FAQ + identical Terms of Service + similar leak site structure (4) "Honest and simple pentesters" branding (signature): distinctive cluster-defining leak site branding per Bleeping Computer (5) ".8base + .eight + .elbie + .faust + .LIZARD" file extensions (signature): signature Phobos variant extension lineage (6) helpermail@onionmail.org contact email (signature): consistent since June 2022 per Bleeping Computer (7) admlogs25.xyz payload domain + SystemBC link (signature): per VMware, SystemBC proxy malware C2 obfuscation association (8) "cartilage" ransom note top corner branding + purple background HTA (signature) (9) Double-extortion (signature): encryption + data leak threat per Bleeping Computer (10) February 2025 DOJ Berezhnoy + Glebov Phobos operators arrests (signature): $16M+ extortion, 1000+ entities targeted, coordinated international operation infrastructure dismantling (11) Europol + FBI + NoMoreRansom decryptor November 2024+ (signature): defeated 8Base encryption capability for affected victims The cluster fills the March-2022-onward + Phobos- v2.9.1-variant + SmokeLoader-embedded-payload + RansomHouse-rebrand-suspected + "honest pentesters" branding + DOJ Phobos arrests position in the post- Conti-takedown 2022-2024 RaaS fragmentation operators cell.

Aliases

19
8base8base ransomware8 base8base group8base ransomware group8base operators8base team8base real pentesters8base raaseightbase8base phobos v2.9.1 variant8base smokeloader phobos delivery8base honest simple pentesters branding8base ransomhouse suspected rebrandphobos 8base eight file extensionphobos crysis dharma ransomware familyhelpermail@onionmail.org contact email signatureadmlogs25.xyz payload hosting domain systembcbase_8 berezhnoy glebov phobos arrests february 2025

Notable Campaigns

10
2025U.S. DOJ Phobos Operators Berezhnoy + Glebov Arrests + Infrastructure Dismantling (February 2025)
2024-2025Europol + FBI + NoMoreRansom Phobos + 8Base Decryptor Release (November 2024+)
20238Base Data Leak Site Launch, Honest Pentesters Branding (May 2023)
20238Base June 2023 Spike, 35 Victims (June 2023)
20238Base RansomHouse-Rebrand-Suspected Signature (June 2023)
20238Base SmokeLoader Embedded Payload Signature
2022-2026Continued Industry Reference Status (2022-2026)
2022-20238Base Quiet Period (2022 - Early 2023)
2022-20238Base Phobos v2.9.1 Customized Variant Signature
20228Base Origin, March 2022

Attribution & Reporting

Attributed by
VMware Carbon Black (canonical June 2023 8Base + Phobos analysis + RansomHouse-rebrand-suspected identification)Cisco Talos (Guilherme Venere canonical November 2023 two-part Phobos variant analysis)The Hacker News (canonical November 2023 Phobos variant via SmokeLoader coverage)Bleeping Computer (canonical June 2023 + 8Base ramp-up coverage + tracking)SecurityAffairs (canonical 8Base + Phobos coverage including February 2025 Berezhnoy + Glebov arrests + November 2024 free decryptor)SC Media (canonical June 2023 double extortion ramp-up coverage)Avertium (canonical August 2024 double extortion group analysis)ISH Tecnologia (Caique Barqueta) (canonical July 2023 hackers-increase-double-extortion analysis)Rewterz (canonical July 2023 8BASE threat alert)VulnerX (canonical 8Base Group Phobos analysis)RedPacket Security (canonical 8Base SmokeLoader coverage)U.S. Department of Justice (canonical February 2025 Berezhnoy + Glebov indictment)Europol + FBI + NoMoreRansom (canonical November 2024+ decryptor release)Heimdall Threat Intel (canonical SHA-256 sample identification)Michael Gillespie ID Ransomware (canonical .eight + .8base extension tracking)
Key reporting
reportThe Hacker News: 8Base Group Deploying New Phobos Ransomware Variant via SmokeLoader (November 2023), canonical industry coverage
reportCisco Talos (Guilherme Venere): canonical two-part Phobos variant analysis November 2023
reportVMware Carbon Black: canonical June 2023 8Base + Phobos analysis + RansomHouse-rebrand-suspected identification
reportBleeping Computer: 8Base ransomware gang escalates double extortion attacks in June (June 27, 2023), canonical ramp-up coverage
reportSC Media: Double extortion attacks by 8Base ransomware ramp up (June 29, 2023)
reportAvertium: The Double Extortion Group, 8Base (August 2024), canonical retrospective
reportSecurityAffairs: 8base ransomware operators use a variant of Phobos ransomware (November 2023) + February 2025 DOJ arrests + November 2024 decryptor
reportISH Tecnologia (Caique Barqueta): canonical hackers-increase-double-extortion analysis (July 2023)
reportRewterz: canonical 8BASE threat alert (July 2023)
reportU.S. Department of Justice: canonical February 2025 Berezhnoy + Glebov indictment
reportEuropol + FBI + NoMoreRansom: canonical November 2024+ Phobos + 8Base decryptor
reportHeimdall Threat Intel: canonical sample SHA-256 identification
reportMichael Gillespie ID Ransomware: canonical .eight + .8base extension tracking

Operational

State sponsor

Russia-based organized cybercrime, Phobos ransomware umbrella attribution. Operators Roman Berezhnoy + Egor Glebov (Russian nationals) charged by U.S. Justice Department February 2025 for operating Phobos ransomware group.

Operationally separate from state- sponsored APT activity. Attribution chain: (1) VMware Carbon Black canonical June 2023 RansomHouse-rebrand-suspected analysis: per VMware + Bleeping Computer + ISH Tecnologia: "The first similarity noticed would be the comparison of the ransom note using the Doc2Vec neural language processing model. During the analysis, the 8base ransom note had a 99% match with the RansomHouse ransom note.

In addition, the blog used by both groups of ransomware appear to be identical." Operationally significant suspected operator-relation tradecraft. (2) The Hacker News canonical November 2023 + Cisco Talos canonical Phobos v2.9.1 variant + Guilherme Venere analysis: per The Hacker News: "8Base Group Deploying New Phobos Ransomware Variant via SmokeLoader." Per Cisco Talos researcher Guilherme Venere two-part analysis: 8Base uses customized Phobos v2.9.1 ransomware loaded via SmokeLoader. (3) Bleeping Computer + VMware canonical June 2023 spike + 67-107 victims tracking: per Bleeping Computer June 2023 + VMware: 8Base saw massive activity spike May-June 2023 with 35 victims in May + 67 victims by mid-2023 + 107+ by July 2023, focusing on SMBs in finance + manufacturing + business services + IT in U.S. + Brazil.

(4) U.S. Justice Department canonical February 2025 Berezhnoy + Glebov Phobos arrests: per SecurityAffairs: "In February 2025, the U.S. Justice Department unsealed charges against Russian nationals Roman Berezhnoy and Egor Glebov for operating a Phobos ransomware group.

They allegedly targeted over 1,000 public and private entities worldwide, extorting more than $16 million in ransom. Both were arrested in a coordinated international operation that also dismantled the group's infrastructure and led to further arrests." (5) Europol + FBI + NoMoreRansom canonical November 2024+ free decryptor release: per SecurityAffairs: free decryptor for Phobos + 8base ransomware released. "The tool works on files with extensions like .phobos, .8base, .elbie, .faust, and .LIZARD, and may support others." Operational mission objective: Financial extortion via Phobos variant ransomware encryption + data theft double-extortion. Per VMware: "8base ransomware group first came to prominence in early March 2022, remaining relatively quiet after only a few attacks.

They operate like other ransomware groups, through double extortion (encryption + data leakage).

" Operational target profile
  • U.S. + Brazil primary geographic targets per VMware June 2023.
  • SMBs primary target size per VMware.
  • Finance + manufacturing + business services + IT primary sectors per VMware.
  • 67 victims by May 2023, 107+ by July 2023 per various tracking The cluster fills the March-2022-onward + Phobos- v2.9.1-variant + SmokeLoader-embedded-payload + RansomHouse-rebrand-suspected + RaaS-affiliate-of- Phobos position in the post-Conti-takedown 2022-2024 RaaS fragmentation operators cell.
Motivations
financial_extortion_double_extortion_phobos_variant_ransomware, smb_targeting_finance_manufacturing_business_services_it, phobos_v2_9_1_customized_ransomware_variant_capability, smokeloader_embedded_payload_delivery_signature_tradecraft, ransomhouse_rebrand_suspected_capability, honest_simple_pentesters_branding_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)8/60 · 13%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SMOKELOADER EMBEDDED ENCRYPTED PAYLOAD DELIVERYSMOKELOADER PROCESS MEMORY RANSOMWARE INJECTION
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin