HomeSecurity8Base ransomware: Attacks increased in June

8Base ransomware: Attacks increased in June

The 8Base is targeting organizations around the world, with attacks increasing since early June.

8Base ransomware

This particular ransomware gang first appeared in March 2022. At that time, it had not attracted attention, as it had only recorded a few notable attacks.

However, since early June, the ransomware operation has seen increased activity, targeting multiple companies across various industries and carrying out double extortion (like most ransomware groups).

So far, the 8Base group has listed 35 victims on its data leak website . On some days, six victims’ names were listed at once. This is a significant increase compared to March and April.

The gang's data leak website appeared in May 2023, with the extortion gang claiming to be "honest and simple" pentesters.

See also: Nearly 40% increase in Ransomware attacks worldwide

“ We are honest and straightforward pentesters. We offer companies the most loyal conditions for the return of their data ,” their data breach website states . “ This list contains only those companies that have neglected the privacy and importance of their employees’ and customers’ data .”

Relationship with other ransomware groups

In a new report from VMware 's Carbon Black team , researchers say that recent 8Base attacks indicate that it is a rebrand of another ransomware company, possibly RansomHouse.

RansomHouse is a ransomware group that claims not to be carrying out encryption attacks. Instead, it works with ransomware operations to sell data. However, according to BleepingComputer, the attackers are using ransomware in attacks , such as White Rabbit or MARIO, which has also been linked to the FIN8 group.

See also: 'Wagner' ransomware targets computers in Russia

VMware researchers suspect that the 8Base ransomware group is an offshoot of RansomHouse. This assumption is based on the identical ransom used by the two groups and the very similar language and content observed on data leak websites.

However, it is not certain whether 8Base was actually created by members of RansomHouse or if it is simply another ransomware operation copying RansomHouse.

8Base ransomware: Attacks increased in June

Technically, 8Base uses a customized version of the Phobos v2.9.1 ransomware, which is loaded via SmokeLoader. Phobos is a RaaS operation targeting Windows. It first appeared in 2019 and shares many code similarities with the Dharma.

In recent attacks, it was observed that when encrypting files, the ransomware appended the .8base.

Additionally, VMware analysts found that 8Base uses the “admlogs25[.]xyz” domain to host payloads, which are related to SystemBC, a proxy malware used by various ransomware groups.

These findings indicate that the 8Base ransomware gang has been carrying out encryption attacks for at least a year, but only recently became more well-known with the launch of the data.

See also: MOVEit attacks: Siemens Energy confirmed data breach

8Base is just now starting to attract analyst attention. As a result, we don't know much about the team's techniques. You can learn more details in VMware's report

Ransomware is a serious threat to individuals and businesses , and it is essential to take steps to protect against it. Prevention is the best approach. Keep your software up to date, be cautious of emails and website links, and regularly back up critical data. By doing the above, you can reduce the risk of falling victim attack . By taking proactive measures and being aware of the latest threats, you will be able to keep your data safe and stay one step ahead of potential attackers.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS