8Base
Russian-speaking ransomware-as-a-service operation that emerged in 2022 as a Phobos affiliate, deploying a modified Phobos encryptor with double-extortion tactics. Targeted small and medium-sized businesses across finance, manufacturing, business services, and IT — over 1,000 victims claimed and an estimated $16M extracted. Disrupted on 10 February 2025 by **Operation Phobos Aetor**, a multi-jurisdiction action coordinated by the U.K. NCA, FBI, Europol, and police agencies from Bavaria, Belgium, Czechia, France, Germany, Japan, Romania, Spain, Switzerland, and Thailand. Four Europeans were arrested in Phuket; Russian nationals Roman Berezhnoy (33) and Egor Nikolaevich Glebov (39) were named as the operators of the 8Base / Affiliate 2803 RaaS organisation.
Aliases
Motivations
Target sectors
Target countries
Diamond Model
Caltagirone / Pendergast / Betz 2013 — four-vertex attribution framework.
MITRE ATT&CK techniques
Timeline
1 eventIndicators of compromise
3 indicators| Type | Value | First seen | Source |
|---|---|---|---|
| SHA-256 | family · Phobos 8Base ransom note dropped after Phobos-based encryption in the campaigns documented by VMware Carbon Black researchers. | May 31, 2023 | VMware Carbon Black |
| SHA-256 | family · Phobos Phobos-derived 8Base ransomware payload analyzed by VMware Carbon Black in the June 2023 spike of double-extortion intrusions. Loaded via SmokeLoader with SystemBC for C2. | May 31, 2023 | VMware Carbon Black |
| Domain | family · SystemBC SystemBC C2 / staging domain in the 8Base infrastructure cluster (admlogs25, admhexlogs25, admlog2, serverlogs37, dnm777, dexblog, blogstat355, blogstatserv25, wlaexfpxrs) listed by VMware Carbon Black. | May 31, 2023 | VMware Carbon Black |
Related actors
shared ATT&CK techniques- ?? · UnknownAkira4 shared techniques
- ?? · UnknownHive4 shared techniques
- ?? · UnknownQilin4 shared techniques
- ?? · UnknownRansomHub4 shared techniques
- ?? · UnknownALPHV/BlackCat3 shared techniques
- RU · RussiaDarkSide3 shared techniques
References
cite this page
Threat Intel Tracker. (2026-05-19). 8Base — actor profile. Retrieved from https://threatintel.local/actors/8base