Inactive ransomware operator
← All groups8Base
458 victims indexed · first seen 3 years ago · last activity 1 year ago
At a glance
- Status
- inactive
- First seen
- 3 years ago
- Last activity
- 1 year ago
- Onion sites
- 4 known endpoints
- Primary sector
- Business Services · 50 hits
About
References
10 linksExternal sources curated by the MISP threat-intel community.
- ransomlook.io/group/8base
- trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-8base
- sentinelone.com/anthology/8base/
- checkpoint.com/cyber-hub/threat-prevention/ransomware/8base-ransomware-group/
- cyberint.com/blog/research/all-about-that-8base-ransomware-group-the-details/
- fortinet.com/blog/threat-research/ransomware-roundup-8base
- hhs.gov/sites/default/files/8base-ransomware-analyst-note.pdf
- eye.security/blog/8base-ransomware-investigation-uncovers-surprising-insights
- axios.com/2025/02/11/fbi-europol-8base-ransomware-takedown
- europol.europa.eu/media-press/newsroom/news/key-figures-behind-phobos-and-8base-ransomware-arrested-in-international-cybercrime-crackdown
Timeline
18 monthsTop countries
Top sectors
MITRE ATT&CK
3 techniques · 3 tacticsTactics
Recent victims
Loading…
Onion infrastructure
4 known- http://92.118.36.204
- http://basemmnnqwxevlymli5bs36o5ynti55xojzvn246spahniugwkff2pad.onion
- http://xb6q2aggycmlcrjtbjendcnnwpmmwbosqaugxsqb4nx6cmod3emy7sad.onion
- http://xfycpauc22t5jsmfjcaz2oydrrrfy75zuk6chr32664bsscq4fgyaaqd.onion
Source
Updated 1 year agoData on this page is sourced from the group's own leak posts, cross-checked with public ransomware trackers (RansomLook, ransomware.live, RansomWatch), MITRE ATT&CK, and our own Tor and Telegram crawlers. This is a public observatory page — share freely.
