8Base is a financially motivated ransomware and extortion operation that became highly active in 2023. It uses a customized, Phobos-derived ransomware payload, commonly identified by 8Base-specific branding, and combines data theft with file encryption and public victim shaming through a leak site. Its leak-site activity has affected a broad range of industries, with Western organizations comprising much of the reported victim set. 8Base has also been prominent among ransomware actors publicly listing Japanese organizations. Reported intrusions have involved SmokeLoader for delivery and SystemBC for proxying command-and-control traffic, payload delivery, and potential data exfiltration. Observed operator activity includes deployment of remote-access software, LSASS credential dumping, creation of processes using existing user tokens, privilege elevation, PowerShell execution, persistence, and defenses impairment. The malware establishes persistence, deletes backups and shadow copies, disables recovery and firewall protections, enumerates drives, and encrypts data. 8Base is associated with encryption and data-leak extortion, although its operational relationship with the Phobos ransomware-as-a-service ecosystem and with RansomHouse has not been conclusively established. Reporting has indicated that the 8Base leak site has at times been used to publish data obtained by Phobos-affiliated operators, including Faust. Public claims also linked 8Base to a 2024 ransomware incident involving a Vietnamese subsidiary of Japan-based Nidec Corporation, where Everest separately sought extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as one of several ransomware families tied to Woodgnat/KongTuke.
Mentioned only as one of the groups that claimed responsibility for a separate 2024 ransomware attack against another Nidec division.
Named as one of the ransomware groups publicly linked to Woodgnat as a downstream partner or affiliate receiving sold access.
Previously claimed a separate ransomware-related extortion incident involving Nidec's Vietnam-based Nidec Precision division in 2024.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.