25/11/2024
Blog technique
Dissecting 8Base: the anatomy of a cybercriminal threat actor
L'équipe SOC CERT CTI CWATCH
Dissecting 8Base: the anatomy of a cybercriminal threat actor
This report jointly prepared by Almond CWATCH and Amossys teams highlights the connection between 8Base a group of cybercriminals targeting small companies since 2022 and Phobos, a well-known ransomware used in the wild since 2019 and primarily targeting Windows systems. 8Base was mainly active during the end of 2023, and we’ve recently seen its reappearance in October 2024, which prompted us to publish this document.