8Base is a ransomware operation active from at least May 2023 and heavily active from mid-2023 into 2024. The reporting describes it as a financially motivated cybercrime actor and ransomware brand, not a nation-state actor. It is repeatedly identified as an operator or affiliate user of Phobos ransomware, including custom branding such as the ".8base" file extension and modified Phobos ransom notes. Multiple sources also describe 8Base as a visibility-focused extortion operation that relied heavily on victim disclosures through Tor-based leak sites, mirrored at times on surface-web infrastructure, and used staged disclosure workflows and Telegram-based communications. The group has targeted a broad range of sectors and organizations. Reported victims or impacted organizations mentioned in the content include Nidec Precision in Vietnam in 2024, the UN Development Programme in 2024, and Japanese organizations more broadly, where 8Base ranked among the leading leak-site actors over a five-year period. Western organizations reportedly made up the majority of its victims, and StealthMole monitoring recorded 459 victims attributed to 8Base between May 2023 and February 2025. The content links 8Base intrusions and infrastructure to Phobos, SmokeLoader, and SystemBC. VMware Carbon Black reported that 8Base used SmokeLoader and SystemBC during intrusions, with SmokeLoader providing initial obfuscation, unpacking, and loading of Phobos ransomware. SystemBC is described as a SOCKS5 proxy/backdoor used to conceal command-and-control traffic and support command execution, payload delivery, and exfiltration. Cisco Talos also linked an 8Base sample to the domain admlogs25[.]xyz, assessed as associated with SystemBC. 8Base is also repeatedly referenced as a downstream ransomware customer of the initial access broker Woodgnat, also known as KongTuke. Reporting links Woodgnat and related tooling such as ModeloRAT and Mistic to attacks involving Qilin, Interlock, Rhysida, Akira, 8Base, and Black Basta, indicating that 8Base has been part of a broader cybercrime access ecosystem. The group maintained multiple onion domains, a data leak site, Telegram channels, and at least some surface-web infrastructure. Historical analysis cited in the content found overlap between malware hashes and infrastructure associated with ALPHV, BianLian, Knight, and Play, suggesting 8Base likely operated within a shared ransomware ecosystem rather than as a fully independent operation. The content also notes law-enforcement action against 8Base around November 2024, later seizure of its primary leak site, and subsequent closure or dormancy of the brand, though technical artifacts and historical infrastructure persisted after public activity declined. Known aliases and related names directly mentioned in the content: 8Base. Related ecosystems and associated groups mentioned in the content include Phobos, Woodgnat, and KongTuke.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as one of the groups that claimed responsibility for a separate 2024 ransomware attack against another Nidec division.
Named as one of the ransomware groups publicly linked to Woodgnat as a downstream partner or affiliate receiving sold access.
Previously claimed a separate ransomware-related extortion incident involving Nidec's Vietnam-based Nidec Precision division in 2024.
Named as a ransomware group linked to the malware activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.