The “victim shaming” website operated by the cybercriminals behind 8Base – currently one of the most active ransomware groups – was leaking information that the criminal group likely did not intend to make public earlier today. The leaked information suggests that at least some of the website’s code was written by a 36-year-old programmer living in the Moldovan capital.
See also: Bumblebee malware: New attacks abuse WebDAV folders

8Base maintains a darknet website that is only accessible via Tor. The website lists hundreds of organizations and companies that are considered victims of hacks, as they refused to pay ransom to prevent the publication of their stolen data.
The 8Base darknet page also has a built-in chat feature, presumably so that 8Base victims can communicate and negotiate with the ransomware administrators. This chat feature, powered by the Laravel web application framework, works well when it comes to sending information to the website (i.e. by sending a “POST” request).
See also: Should employees who constantly click on phishing emails be fired?
However, if someone tried to retrieve data from the same chat service (i.e., by making a “GET” request), the website has been producing an incomprehensibly verbose error message ever since.

This error page revealed the actual Internet address of the hidden Tor service hosting the 8Base website: 95.216.51[.]74, which according to DomainTools.com is a server in Finland connected to the German-based hosting giant Hetzner.
But that's not the interesting part: Scrolling down the lengthy error message, we can see a link to a private Gitlab server called Jcube-group: gitlab[.]com/jcube-group/clients/apex/8base-v2. Digging further into this Gitlab account, we can find some strange data points available in the JCube Group's public code repository.
For example, this “status.php” page, which was committed to the JCube Group Gitlab repository about a month ago, includes code that makes several references to the term “KYC” (e.g. KYC_UNVERIFIED, KYC_VERIFIED, and KYC_PENDING).
See also: Auckland Transport: Medusa group stole data
This is odd, as a set of FAQs on 8Base’s Darknet website includes a section titled “special offers for journalists and reporters,” which states that the criminal group is open for interviews, but journalists must prove their identity before any interviews can take place. 8Base’s FAQ refers to this authentication process as “KYC,” which stands for “Know Your Customer.”

The 8Base darknet website also has a publicly accessible “admin” login page, which includes an image of a commercial airliner that appears to be at an airport. Next to the photo of the plane is a message that says: “Welcome to 8Base. Admin login to the 8Base dashboard.”

Right-clicking on the 8Base admin page and selecting “View Source” produces the HTML code for the page. This code is almost identical to a “login.blade.php” page that was created and committed to the JCube Group’s Gitlab repository about three weeks ago.
The person responsible for the JCube Group code appears to be a 36-year-old developer from Chisinau, Moldova, named Andrei Kolev. Mr. Kolev’s LinkedIn page lists him as a full-stack developer at JCube Group and that he is currently looking for work. The Jcubegroup[.]com homepage lists an address and phone number that official Moldovan business records confirm are linked to Mr. Kolev.
The posts on the Twitter account for Mr. Kolev (@andrewkolev) are all written in Russian and refer to several online businesses that are no longer in operation, including pluginspro[.]ru.
Asked for comment via LinkedIn, Mr. Kolev said he had no idea why the darknet site 8Base was selecting code from the “clients” folder of the private JCube Group repository on Gitlab, nor how the name 8Base was included.
Mr. Kolev shared a screenshot of his current projects, but quickly deleted it. However, KrebsOnSecurity captured a copy of the image before it was removed:

KrebsOnSecurity: Within minutes of explaining why I contacted Mr. Koleff and analyzing the process of finding this connection, the 8Base website changed and the error message linking to the JCube Group’s private Gitlab repository was no longer displayed. Instead, attempting to perform the same “GET” method described above resulted in a “405 Method Not Allowed” error page being returned from the 8Base website.
Mr. Koleff claimed he knew nothing about the now-removed error page on 8Base's website that referenced his private Gitlab repository, and said he deleted the screenshot from the LinkedIn conversation because it contained personal information.
Ransomware groups are known to hire remote developers for specific projects without revealing exactly who they are or how the new hire's code is intended to be used, and it is possible that one of Mr. Kolev's clients is 8Base.
A recent VMware blog post calls the 8Base ransomware group “a powerful player” that remained relatively unknown despite a huge increase in its activity in the summer of 2023.
According to VMware, what is particularly interesting about 8Base's communication style is the use of expressions that are significantly reminiscent of another well-known cybercriminal group: RansomHouse.
Information source: krebsonsecurity.com
