GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 11-Feb-2025 00:27:29 JST Kevin Beaumont Kevin Beaumont

    8base ransomware group has apparently been seized or done an exit scam.

    Two of its Tor portals say "This hidden site and the criminal content have been seized by the Bavarian State Criminal Police Office on behalf of the Office of the Public Prosecutor General in Bamberg"

    They had been hitting some high profile targets in recent times.

    #threatintel #ransomware

    In conversation about 5 months ago from cyberplace.social permalink

    Attachments


    1. https://cyberplace.social/system/media_attachments/files/113/980/285/199/130/911/original/36da7258b89961df.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 11-Feb-2025 00:33:13 JST Kevin Beaumont Kevin Beaumont
      in reply to

      The text comes from the HTML source btw.

      8base weren't particular great at OPSEC, e.g. their Tor server was blatantly publicly visible on the plain internet for a while - it also had SSH running with the same host signature that LockBit 3.0 use.

      In conversation about 5 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/980/307/473/118/851/original/ff435b2d2a1ec364.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 11-Feb-2025 00:36:28 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • BSI

      hey @bsi - did u seize 8base ransomware portal?

      In conversation about 5 months ago permalink

      Attachments


    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 11-Feb-2025 00:48:40 JST Kevin Beaumont Kevin Beaumont
      in reply to

      based on the timestamps, apparently the portal changed yesterday. Their last victim post was 10 days ago. Has gone from Nginx to Apache webserver on Debian.

      In conversation about 5 months ago permalink

      Attachments


      1. https://cyberplace.social/system/media_attachments/files/113/980/364/337/953/127/original/ed966307dd7093bb.png
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 11-Feb-2025 01:42:54 JST Kevin Beaumont Kevin Beaumont
      in reply to
      • cR0w :cascadia:

      Law enforcement confirm they did a takedown of 8base ransomware group. You heard it here on Mastodon first thanks to @cR0w

      https://techcrunch.com/2025/02/10/global-police-operation-seizes-8base-ransomware-gang-leak-site/

      #threatintel #ransomware

      In conversation about 5 months ago permalink
    • Embed this notice
      Kevin Beaumont (gossithedog@cyberplace.social)'s status on Tuesday, 11-Feb-2025 01:56:04 JST Kevin Beaumont Kevin Beaumont
      in reply to

      4 people have been arrested over the 8base Ransomware takedown.

      In Thailand.

      https://www.bleepingcomputer.com/news/legal/police-arrests-4-phobos-ransomware-suspects-seizes-8base-sites/

      In conversation about 5 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.bleepstatic.com
        Police arrests 4 Phobos ransomware suspects, seizes 8Base sites
        from @BleepinComputer
        A global law enforcement operation targeting the Phobos ransomware gang has led to the arrest of four suspected hackers in Phuket, Thailand, and the seizure of 8Base's dark web sites. The suspects are accused of conducting cyberattacks on over 1,000 victims worldwide.
    • Embed this notice
      BSI (bsi@social.bund.de)'s status on Tuesday, 11-Feb-2025 01:59:13 JST BSI BSI
      in reply to

      @GossiTheDog Hi, no, the Bavarian State Criminal Police Office seized the portal on behalf of the Office of the Public Prosecutor in Bamberg, Germany. Best wishes from the BSI

      In conversation about 5 months ago permalink
    • Embed this notice
      BrianKrebs (briankrebs@infosec.exchange)'s status on Wednesday, 12-Feb-2025 01:10:59 JST BrianKrebs BrianKrebs
      in reply to

      @GossiTheDog yeah their developers weren't too swift either:

      https://krebsonsecurity.com/2023/09/whos-behind-the-8base-ransomware-website/

      In conversation about 5 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.