The 8Base is targeting organizations around the world, with attacks increasing since early June.

This particular ransomware gang first appeared in March 2022. At that time, it had not attracted attention, as it had only recorded a few notable attacks.
However, since early June, the ransomware operation has seen increased activity, targeting multiple companies across various industries and carrying out double extortion (like most ransomware groups).
So far, the 8Base group has listed 35 victims on its data leak website . On some days, six victims’ names were listed at once. This is a significant increase compared to March and April.
The gang's data leak website appeared in May 2023, with the extortion gang claiming to be "honest and simple" pentesters.
See also: Nearly 40% increase in Ransomware attacks worldwide
“ We are honest and straightforward pentesters. We offer companies the most loyal conditions for the return of their data ,” their data breach website states . “ This list contains only those companies that have neglected the privacy and importance of their employees’ and customers’ data .”
Relationship with other ransomware groups
In a new report from VMware 's Carbon Black team , researchers say that recent 8Base attacks indicate that it is a rebrand of another ransomware company, possibly RansomHouse.
RansomHouse is a ransomware group that claims not to be carrying out encryption attacks. Instead, it works with ransomware operations to sell data. However, according to BleepingComputer, the attackers are using ransomware in attacks , such as White Rabbit or MARIO, which has also been linked to the FIN8 group.
See also: 'Wagner' ransomware targets computers in Russia
VMware researchers suspect that the 8Base ransomware group is an offshoot of RansomHouse. This assumption is based on the identical ransom used by the two groups and the very similar language and content observed on data leak websites.
However, it is not certain whether 8Base was actually created by members of RansomHouse or if it is simply another ransomware operation copying RansomHouse.

Technically, 8Base uses a customized version of the Phobos v2.9.1 ransomware, which is loaded via SmokeLoader. Phobos is a RaaS operation targeting Windows. It first appeared in 2019 and shares many code similarities with the Dharma.
In recent attacks, it was observed that when encrypting files, the ransomware appended the .8base.
Additionally, VMware analysts found that 8Base uses the “admlogs25[.]xyz” domain to host payloads, which are related to SystemBC, a proxy malware used by various ransomware groups.
These findings indicate that the 8Base ransomware gang has been carrying out encryption attacks for at least a year, but only recently became more well-known with the launch of the data.
See also: MOVEit attacks: Siemens Energy confirmed data breach
8Base is just now starting to attract analyst attention. As a result, we don't know much about the team's techniques. You can learn more details in VMware's report
Ransomware is a serious threat to individuals and businesses , and it is essential to take steps to protect against it. Prevention is the best approach. Keep your software up to date, be cautious of emails and website links, and regularly back up critical data. By doing the above, you can reduce the risk of falling victim attack . By taking proactive measures and being aware of the latest threats, you will be able to keep your data safe and stay one step ahead of potential attackers.
Source: www.bleepingcomputer.com
