A coordinated international law enforcement effort has resulted in the arrest of four suspected members of the Phobos ransomware gang in Phuket, Thailand, and the seizure of 8Base’s dark web sites. The suspects, two men and two women from Europe, are accused of launching cyberattacks on over 1,000 victims worldwide and extorting approximately $16 million in Bitcoin.
The operation, codenamed “Phobos Aetor,” involved raids across four locations, leading to the confiscation of laptops, smartphones, and cryptocurrency wallets for forensic examination. Swiss authorities initiated the arrests and have requested the suspects’ extradition to face charges.
According to reports, the individuals carried out ransomware attacks on at least 17 Swiss companies between April 2023 and October 2024. They infiltrated corporate networks, stole sensitive data, and encrypted files, demanding cryptocurrency ransoms to restore access and prevent data leaks. The laundered ransom payments were funneled through cryptocurrency mixing platforms to obscure their final destinations.
Seizure of 8Base Dark Web Sites
The 8Base ransomware group’s dark web sites, including their data leak and negotiation platforms, were also seized as part of the operation. Visitors to the sites now see a law enforcement notice stating that the Bavarian State Criminal Police Office seized them on behalf of the Public Prosecutor General in Bamberg, Germany.
The seizure message confirms the involvement of multiple countries, including Thailand, Romania, Germany, Switzerland, Japan, the U.S., Europol, Czechia, Spain, France, Belgium, and the U.K. Europol and the U.K.’s National Crime Agency (NCA) have verified their roles in the operation.
8Base first emerged in March 2022 but gained significant attention in June 2023 after ramping up attacks and data leaks. Although the group referred to themselves as “pentesters,” cybersecurity analysts noted their operational sophistication, leading to speculation that they could be a rebrand of another cybercrime group.
Attack Methods and Impact
Like other ransomware groups, 8Base infiltrated corporate networks, moved laterally through systems, and exfiltrated sensitive data before deploying the Phobos ransomware encryptor. Encrypted files were appended with either the .8base or .eight extension, and victims were issued ransom notes demanding payments ranging from hundreds of thousands to millions of dollars in exchange for decryption keys and data deletion assurances.
The takedown of the Phobos ransomware gang and the seizure of 8Base’s infrastructure mark a significant victory in the fight against global cybercrime. Authorities continue to investigate the group’s operations, aiming to dismantle any remaining affiliates and disrupt future ransomware activities.
Organizations are advised to strengthen cybersecurity measures, including network monitoring, employee training, and the implementation of robust backup strategies, to mitigate the risk of ransomware attacks.

















Comments