HomeSecurity8Base ransomware group rivals Lockbit in extortion

8Base ransomware group rivals Lockbit in extortion

The new ransomware group, 8Base, is quickly becoming a major player in the hacking market after it managed to amass nearly 40 victims in June, coming in second only to the infamous LockBit ransomware gang.

See also: Hacker behind Gozi malware sentenced to three years in prison in the US

8Base ransomware

The group has attacked nearly 80 organizations since March 2022 and has used the dual extortion tactic of encryption and “name and shame,” according to a new report from VMware.

The 8Base group was responsible for 15% of attacks in May, as the group began publishing data from victims breached between April 2022 and May 2023, according to a report by NCC Group published last week. Ransomware attacks spiked in May, hitting 436 victims. Lockbit 3.0 remained the most active threat actor in 2023, responsible for 78 known victims, accounting for 18% of all incidents tracked in May.

See also: BlackCat ransomware: Promotes Cobalt Strike via WinSCP search ads

The majority of 8Base’s targets are in the industrial sector, according to the NCC group. VMware said it also targets business services, finance, manufacturing and IT industries. So far, the group has recorded 38 victims for June. It uses a data leak website, a Twitter account and a Telegram channel to publicize the names of its victims.

The 8Base group's activity is similar to that of the less active RansomHouse ransomware gang, which buys leaked data, partners with data leak sites, and then extorts money from companies.

The language used on the leak sites, ransom note, and terms of service and FAQ pages of both ransomware groups are eerily similar, VMware said. The two most significant differences between the groups are their graphical user interfaces and the fact that RansomHouse openly hires collaborators , while 8Base does not.

8Base ransomware group rivals Lockbit in extortion

Both groups also use multiple ransomware variants in their campaigns – variants of the Phobos family. Phobos operates as ransomware-as-a-service, and 8Base likely adopted it, adding customizations such as tagging encrypted files with the victim’s ID, the email address support@rexsdata.pro, and a “.8base” extension. 8Base was found to be using version 2.9.1 of Phobos and is loaded using SmokeLoader, VMware said.

See also: Free Akira ransomware decryptor helps recover your files

Malware research website Vx-Underground compared 8Base’s output to the “Big 3” – the Conti, LockBit, and Alphv ransomware groups – which it defines as the “largest and most prolific ransomware groups of recent years.” Vx-Underground believes 8Base is an internal group or subgroup of the LockBit ransomware that decided to form its own group – and predicts that “it will become a major player in the ransomware scene in the coming months.”

Information source: bankinfosecurity.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS