Aller au contenu principal
Retour à la base de rançongiciels
Groupe de rançongiciel

8base

The 8base Ransomware group made its first appearance in early March 2022, remaining somewhat quiet after the attacks. This group operates like other ransomware actors, engaging in double extortion. <BR> However, in mid-May and June 2023, the ransomware operation saw a spike in activity against organizations from various sectors, listing 131 organizations in just 3 months.<BR> The 8base data leak site was created and made available in March 2023, claiming honesty and simplicity in its discourse.<BR> VMware published a report on 8base, drawing some similarities with the ransomware group `RansomHouse`, pointing out resemblances such as the website used by 8base and the ransom notes presented in its attacks.<BR> Interestingly, the 8base Ransomware group does not have its own ransomware developed by the group. Instead, the actors took advantage of other leaked ransomware builders to customize the ransom note and present it to the victim organization as 8base's operation.<BR>Source : https://github.com/crocodyli/ThreatActors-TTPs

Victimes connues455

Niveau de menace

ÉLEVÉ

Tactiques, techniques et procédures (TTP)

CredentialTheft

  • LaZagne
  • Mimikatz
  • NirSoft VNCPassView
  • NirSoft WebBrowserPassView
  • PasswordFox
  • +1 de plus

DefenseEvasion

  • GMER
  • PCHunter
  • ProcessHacker

Exfiltration

  • RClone

LOLBAS

  • PsExec
0

Vérifier si vous êtes touché

Cherchez dans notre base si votre organisation figure sur la liste des victimes de 8base.

Essayez maintenantGratuit⌘K
Exemple

score de risque · catégories de menace · sources · ancienneté · confiance — en une requête

Autres groupes de rançongiciel actifs