8Base
8Base (canonical industry naming per VMware Carbon Black + Cisco Talos + Bleeping Computer + SecurityAffairs + Avertium tracking) is a Phobos v2.9.1 customized variant ransomware operator active since March 2022 with signature SmokeLoader embedded-payload delivery + cluster-defining suspected RansomHouse rebrand operator-relation per VMware Carbon Black June 2023 analysis (99% Doc2Vec ransom note match + identical FAQ + identical Terms of Service)
Russia-based organized cybercrime attribution via Cisco Talos (Guilherme Venere) canonical November 2023 two-part Phobos variant analysis ("8Base utilizes a modified version of the Phobos v2.9.1 ransomware, which is distributed via SmokeLoader. Phobos, an Ransomware-as-a-Service RaaS operation that emerged in 2019, shares code similarities with the Dharma ransomware") + U.S. DOJ February 2025 charges against Russian nationals Roman Berezhnoy + Egor Glebov for operating Phobos ransomware group ("They allegedly targeted over 1,000 public and private entities worldwide, extorting more than $16 million in ransom") + Europol + FBI + NoMoreRansom November 2024+ free decryptor release.
standalone cluster paralleling bianlian + inc_ransom + noescape in v0.1.148 post- Conti-takedown 2022-2024 RaaS fragmentation operators cell.
operational target profile U.S. + Brazil primary geographic targets per VMware June 2023 + SMBs primary target size + finance + manufacturing + business services + IT primary sectors with 67 victims by May 2023 + 107+ by July 2023.
operational attack architecture: (1) cluster-defining Phobos v2.9.1 customized ransomware variant with Dharma/Crysis 2019+ RaaS family code lineage per Cisco Talos + VMware.
(2) cluster-defining SmokeLoader embedded-payload delivery per Cisco Talos November 2023 ("This commodity loader typically drops or downloads additional payloads when deployed. In 8Base campaigns, however, it has the ransomware component embedded in its encrypted payloads, which is then decrypted and loaded into the SmokeLoader process' memory"), unique cluster-defining delivery distinguishing 8Base from typical SmokeLoader external-download-of- payload pattern.
(3) cluster-defining suspected RansomHouse rebrand operator-relation signature per VMware Carbon Black + ISH Tecnologia ("The first similarity noticed would be the comparison of the ransom note using the Doc2Vec neural language processing model. During the analysis, the 8base ransom note had a 99% match with the RansomHouse ransom note. In addition, the blog used by both groups of ransomware appear to be identical"); (4) cluster-defining "honest and simple pentesters" leak site branding distinctive among ransomware operators ("We are honest and simple pentesters. We offer companies the most loyal conditions for the return of their data")
(5) signature .8base + .eight + .elbie + .faust + .LIZARD file extensions Phobos variant lineage + helpermail@onionmail.org contact email consistent since June 2022 per Bleeping Computer.
(6) admlogs25.xyz payload domain + SystemBC proxy malware C2 obfuscation association signature per VMware.
(7) "cartilage" ransom note top corner branding + purple background HTA distinctive ransom note tradecraft.
(8) double- extortion encryption + data leak threat tradecraft; (9) cluster-defining February 2025 U.S. DOJ Berezhnoy + Glebov Phobos operators arrests ($16M+ extortion + 1000+ entities targeted + coordinated international operation infrastructure dismantling)
(10) cluster-defining Europol + FBI + NoMoreRansom decryptor November 2024+ release defeating 8Base encryption capability for affected victims.
cluster fills the March-2022-onward + Phobos-v2.9.1-variant + SmokeLoader-embedded-payload + RansomHouse-rebrand-suspected + "honest pentesters" branding + DOJ Phobos arrests position in post- Conti-takedown 2022-2024 RaaS fragmentation operators cell.
canonical illustration of Phobos variant operator + SmokeLoader embedded delivery + RansomHouse operator-relation + distinctive branding + Phobos operator law enforcement disruption + decryptor release cited in essentially all subsequent ransomware industry analyses through 2022-2026 period.