Bashe, also tracked as APT73 and Eraleign, is a cybercriminal extortion and ransomware actor active since at least April 2024. The group is associated with data-theft extortion and ransomware operations and has used leak-site pressure as part of its coercive model. Reporting also indicates Bashe has repeatedly exaggerated or fabricated intrusions, including falsely claiming responsibility for high-profile breaches and using recycled or previously exposed data to support extortion narratives and attract affiliates. Bashe’s tradecraft includes public victim shaming, exfiltration-themed extortion claims, and reputational pressure designed to force payment even when evidence of a genuine network compromise is weak or absent. In assessed fabricated incidents, the group leveraged public awareness of service outages or other operational disruptions to make false breach claims appear credible. This behavior aligns with psychologically driven extortion in which the actor substitutes demonstrable technical intrusion with spoofed breach attribution, selective data reuse, and leak-site amplification. Known victim claims linked to Bashe include organizations in the United Kingdom and Argentina. Reported targeting includes the financial sector and industrial organizations, including an engineering and construction company involved in public works. Bashe has also been characterized as part of a broader Latin American cybercriminal ecosystem in which some actors emphasize pure extortion and data exposure over encryption, although the available information does not support a definitive national attribution for Bashe itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cybercriminal group focused on data-theft extortion and ransomware that allegedly fabricated a breach claim against Hargreaves Lansdown, likely using fake leaked data and exploiting recent IT outages to support a false extortion narrative.
Regional ransomware/extortion group active in Latin America, claiming compromise of an Argentine engineering and construction firm and noted for frequently fabricating breach claims using public or previously leaked data.
A cybercriminal group focused on data-theft extortion and ransomware that allegedly listed Hargreaves Lansdown as a victim, but the content assesses with high confidence that the claimed breach was fabricated to support extortion and boost credibility.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.