Summary: [/subscribe_to_unlock_form]
Summary: [emaillocker id="1283"]
The 8Base ransomware group has gained attention recently due to a significant increase in their activity during the summer of 2023. Despite their sudden surge, the group has managed to maintain a low profile. Employing a combination of encryption and "name-and-shame" tactics, 8Base coerces victims into paying ransoms. Their targets span across various industries, indicating an opportunistic approach. The efficiency and speed displayed by 8Base suggest that they are not a newly formed group but rather an established and mature organization. Current evidence indicates striking similarities between 8Base's operations and those of previous ransomware attacks. It is evident that the group has been active since March 2022, with a significant surge in activity observed in June 2023.
8Base describes itself as "simple pen testers" on their leak site, which provides victim information and multiple contact methods. The language used by 8Base in their communications bears a striking resemblance to another known group called RansomHouse. The top industries targeted by 8Base include Business Services, Finance, Manufacturing, and Information Technology. Upon closer examination, significant similarities were found between 8Base and RansomHouse. A comparison of their respective ransom notes using Natural Language Processing revealed a 99% match. Additionally, the language used on their leak sites, as well as their Terms of Service and FAQ pages, was nearly identical. The key differences lie in RansomHouse's active promotion of partnerships and recruiting efforts, which 8Base does not engage.
One major challenge in understanding 8Base's operations is the lack of information about their specific ransomware variant. It is possible that 8Base, like RansomHouse, employs different types of ransomware obtained from dark markets. A sample of the ransomware used by 8Base revealed the use of Phobos ransomware version 2.9.1, customized with their own branding. The sample was downloaded from a domain associated with SystemBC, a proxy and remote administration tool used by other ransomware groups.
8Base remains a highly active ransomware group, targeting smaller businesses. Whether they are an offshoot of Phobos or RansomHouse is still uncertain, but their similarities to RansomHouse and the use of Phobos ransomware are notable. As 8Base continues its operations, it is crucial for organizations to implement robust endpoint detection solutions.
Threat Profile:
| Tactic | Technique Id | Technique |
| Persistence | T1547 | Boot or Logon Autostart Execution |
| Defense Evasion | T1134 | Access Token Manipulation |
| T1562 | Impair Defenses | |
| T1027 | Obfuscated Files or Information | |
| Discovery | T1135 | Network Share Discovery |
| Impact | T1490 | Inhibit System Recovery |
| T1486 | Data Encrypted for Impact |
References:
The following reports contain further technical details:
[/emaillocker]