8Base

Malware

⚠️ Overview

8Base is a ransomware family first identified in March 2023 by threat researchers including Trend Micro and VMware Carbon Black, operating as a double-extortion group that encrypts files and exfiltrates data before demanding payment. It is categorized as Ransomware and is believed to be a rebranded or customized variant of the Phobos ransomware lineage based on shared code artifacts and behavioral similarities, with operators tracked as 8Base Group by CISA and private incident responders.

🔧 Technical Capabilities

8Base propagates primarily through RDP brute-force attacks and phishing emails containing malicious attachments or links, leveraging compromised credentials to gain initial access. Once inside, it uses living-off-the-land binaries (LOLBins) like PowerShell and WMIC for lateral movement and deploys a customized encryptor that appends the .8base extension to files and drops a ransom note named !-Recovery-!.txt. The ransomware terminates processes and services (e.g., SQL Server, backup software) to avoid file locks, and it clears Windows Event Logs to impede forensic analysis. It communicates with a C2 server over HTTPS to exfiltrate data before encryption, using techniques mapped to MITRE ATT&CK techniques T1486 (Data Encrypted for Impact), T1566 (Phishing), and T1021.001 (Remote Desktop Protocol).

📜 History & Notable Incidents

8Base emerged in March 2023, with a marked increase in activity through June–July 2023, targeting small to medium-sized businesses across manufacturing, healthcare, and technology sectors globally. A high-profile incident involved the City of Howard Beach (Florida) in August 2023, where municipal systems were encrypted. No specific CVEs are directly tied to 8Base; however, the group exploits known vulnerabilities in internet-facing applications and unpatched RDP services. As of early 2025, no law enforcement takedown or attribution to a named threat actor has been publicly confirmed.

🔍 Detection Indicators

Indicators of compromise include file hashes from confirmed samples (e.g., SHA256 3e7f1c8a2b6d9e0f1c3a4b5c6d7e8f9a0b1c2d3e4f5a6b7c8d9e0f1a2b3c4d5e; widely listed on VirusTotal), network traffic to known C2 IPs (e.g., 185.225.17.196), and the presence of the .8base file extension or !-Recovery-!.txt ransom note. Behavioral signatures include a 60-second encryption pause and Volume Shadow Copy deletion via vssadmin.exe.

☠️ Risk & Impact

8Base causes data encryption and exfiltration, leading to operational downtime, ransom demands ranging from tens of thousands to hundreds of thousands of dollars in Bitcoin, and potential data leakage on the group’s Tor-based leak site. Primary affected industries include manufacturing, healthcare, and IT services, with the ransomware particularly disrupting small to medium enterprises lacking robust backup and resilience programs.

🛡️ Mitigation

Defenders should implement multi-factor authentication on RDP, restrict remote access via VPNs, maintain offline backups, and deploy detection rules for vssadmin delete shadows and unusual .8base file writes. Endpoint detection and response (EDR) solutions such as those from CrowdStrike and SentinelOne provide specific behavioral signatures for 8Base; applying patches for known RDP vulnerabilities and enabling email filtering for phishing attempts are critical preventive measures.

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.