top of page

Bashe Ransomware Group: Dark Web Data Leak Case Study

  • securedmonk
  • Jul 6
  • 9 min read

A comprehensive threat intelligence analysis of Bashe's leak infrastructure, attack methodology, victimology, extortion tactics, and defensive recommendations.

Bashe Ransomware Group: Dark Web Data Leak Case Study | Securedmonk

Introduction


Over the last decade, the ransomware landscape has evolved drastically. Threat actors have shifted away from relying solely on file encryption, recognizing that resilient backups often neutralize their leverage. Instead, operators now focus heavily on data theft, public exposure, and psychological pressure a tactic commonly known as double extortion ransomware. To facilitate this, Data Leak Site portals have become a core component of modern cyber extortion, acting as public shaming platforms to coerce victim compliance.


One of the emerging operations that rapidly adopted this model is the Bashe Ransomware Group (also known as APT73). While initially dismissed as a low-tier copycat, it is crucial for defenders to monitor newer syndicates even when their victim count is relatively small. The cybercrime ecosystem's hyper-competitive nature means nascent groups can quickly leverage leaked tools and aggressive marketing to evolve into apex threats.


The purpose of this article is to provide a complete threat intelligence assessment covering Bashe's background, infrastructure, leak site, victimology, attack lifecycle, technical behaviors, and defensive guidance.


Key Takeaway

Modern ransomware campaigns are no longer simply encryption attacks they are sophisticated cyber extortion operations built around data theft, public disclosure, and reputational damage.



Executive Threat Intelligence Summary


Before diving into the detailed analysis, this section serves as an executive briefing for security leaders and SOC analysts regarding Bashe ransomware operations.

Bashe is a financially motivated cybercriminal syndicate operating under the RaaS model. Driven by the lure of high financial yields and enabled by the availability of enterprise-grade leaked malware builders, the group actively targets mid-to-large-scale enterprises and sovereign government entities. The group utilizes standard double-extortion strategies, combining file encryption with the threat of public data release. Its operational model initially relied on theatrical fraud and fabricated claims to establish relevance, but it has since matured into a highly capable threat.


  • First Observed: Mid-April 2024

  • Known Aliases: APT73, Eraleign, APT73 threat actor

  • Ransomware Type: LockBit 3.0 (Black) Leaked Builder Derivative

  • Leak Site Availability: Active on the Tor network

  • Geographic Focus: Global (North America, Europe, Middle East, Asia-Pacific)

  • Industries Targeted: Industrials, Utilities, Government, Financial Services, Technology

  • Confidence Level: High (Capabilities verified via leak site analysis and attributed payload)



Who are Bashe Ransomware Group (APT73)?


Bashe emerged in the threat landscape in mid-April 2024. Researchers and threat intelligence organizations, including CloudSEK and Vectra AI, first documented its activity operating a Tor-based leak site hosted in the Czech Republic. The group adopted the name "Bashe"—derived from a Chinese idiom denoting insatiable greed—and provocatively self-designated as "APT73" to artificially inflate its brand and project an aura of elite, state-sponsored capability.  

Intelligence strongly indicates that Bashe is not an entirely new ransomware family. Instead, it was founded by an alleged former affiliate of the LockBit syndicate following the global law enforcement disruption known as Operation Cronos in February 2024. The group operates on a standard Ransomware-as-a-Service (RaaS) model. Because RaaS relies on independent Initial Access Brokers, a Bashe ransomware affiliate is typically responsible for network intrusion, while the core operators manage the Bashe extortion group infrastructure and negotiation portal.  


Concise Threat Actor Profile:


Bashe Ransomware Group: Dark Web Data Leak Case Study | Securedmonk

A highly active, financially motivated


Bashe ransomware profile characterizes a group that bridged the gap between deceptive marketing and critical infrastructure extortion. Using stolen LockBit code and mimicking LockBit's aesthetic, the group attracts affiliates to execute high-impact attacks against global enterprises.



Timeline of Bashe Activity


The Bashe ransomware campaign demonstrates a rapid transition from illusion to operational reality:

  • April 2024: Emergence of the group. The DLS is launched, heavily mimicking LockBit's infrastructure to absorb displaced affiliates post-Operation Cronos.  

  • December 2024 – January 2025: The "Theatrical Fraud" phase. To build a track record, Bashe publishes fabricated breaches (e.g., Malindo Air, Betclic, Federal Bank India), using recycled public data and dark web combolists.  

  • Mid-2025 to Early 2026: Growth in legitimate affiliate recruitment. The group's APT73 cyber attacks begin targeting genuine victims as sophisticated Initial Access Brokers integrate into the operation.

  • March 2026: A critical escalation milestone. The group successfully compromises UAE critical infrastructure, targeting the Sharjah Electricity, Water, and Gas Authority and the Ministry of Climate Change and Environment.  

  • July 2026: Target saturation. The group consistently posts high-profile global victims, including the Rita Võ Group in Vietnam and government portals in Brazil, confirming its maturation.



Bashe Dark Web Leak Site Analysis


In the modern ecosystem, a Ransomware Leak Portal is both an extortion mechanism and a vital marketing tool. Data leak site analysis of Bashe's portal reveals it was meticulously designed as a near-identical clone of LockBit's user interface.


Bashe Ransomware Group: Dark Web Data Leak Case Study | Securedmonk

The site features identical hierarchical structures for "Contact Us," "How to Buy Bitcoin," "Web Security Bug Bounty," and "Mirrors". By copying LockBit's operational hallmarks, Bashe establishes credibility and familiarity for affiliates seeking a reliable extortion platform. The psychological impact of these public listings is immense; victims face mounting pressure from the media and regulators when they see their brand prominently displayed on the Bashe ransomware leak site.  



Anatomy of a Victim Listing


On the Bashe Leak Blog, individual victim pages are weaponized to maximize pressure. A typical Victim Listing discloses the organization's name, a brief company description, the date of publication, the total size of the stolen archive, and a prominent countdown timer indicating when the data will be dumped.


Bashe Ransomware Group: Dark Web Data Leak Case Study | Securedmonk

To validate their claims and demonstrate the severity of the compromise, attackers routinely publish a small cache of sample documents prior to releasing the complete dataset. This selective preview increases negotiation leverage by proving to the victim—and to business partners, regulators, and the media—that the threat actors possess highly sensitive, internal material.



Leak Infrastructure and Data Publication Process


Beyond the visible blog, the infrastructure enabling Data Publication is robust. Bashe utilizes the AS9009 Autonomous System Number (ASN) for its Tor-based hosting infrastructure in the Czech Republic.


Bashe Ransomware Group: Dark Web Data Leak Case Study | Securedmonk

Downloadable archives are often segmented, hosted on reliable bulletproof servers or distributed via peer-to-peer mechanisms to ensure redundancy. By distributing the data across mirror sites, attackers ensure that even if one server is subjected to a takedown, the leaked information remains accessible. This robust infrastructure is essential for Leak Site Monitoring analysts tracking the distribution of the group's stolen assets.



Types of Data Exposed


The group is highly indiscriminate regarding the data it steals, aiming for maximum Data Extortion leverage. Analysis reveals that Bashe routinely exposes:

  • Corporate Data Breach materials: Internal engineering documents, source code, and strategic communications.

  • Confidential Data Exposure: Financial records, tax documents, and legal contracts.

  • Sensitive Data Leak: Employee identification (e.g., ID cards and academic transcripts leaked from the Philippine DPWH) and customer databases.  

  • Stolen Data: IT credentials, network diagrams, and SCADA documentation that can be sold on secondary cybercrime markets.  

Attackers typically publish detailed file inventories before the full archive release to heighten psychological pressure while retaining the data's exclusivity.



Victim Analysis


To date, Bashe ransomware victims span diverse organizational scales. Based on empirical regularities identified in a 2026 study of over 27,000 leak-site posts across 325 groups, human-operated ransomware target selection is highly selective and predictable.  

Bashe's confirmed targets display standard RaaS victimology: mid-to-large enterprises capable of sustaining multi-million dollar ransom demands.

Target Organization

Country

Industry

Status / Leak Activity

Sharjah Electricity, Water & Gas

UAE

Utilities

Data claimed, high-leverage threats

Dept of Public Works (DPWH)

Philippines

Government

50GB published, ID cards leaked

Brazil

Government

Claimed

Rita Võ Group

Vietnam

Conglomerate

Claimed

Flazio

Italy

Technology

Claimed

Holiday Palace Hotel

Spain

Hospitality

Claimed

 


Industry Targeting Trends


A Bashe ransomware analysis reveals a strong preference for specific sectors that align with macro-ecosystem trends. The group heavily targets the Industrials, Utilities, Financial, and Government sectors.  

These industries are exceptionally attractive because they possess low downtime tolerance. Manufacturing and utilities rely on Operational Technology (OT) and SCADA systems; when integrated IT networks are encrypted, the physical disruption forces organizations to quickly capitulate to ransom demands to restore essential services.  



Geographic Target Analysis


The geographic distribution of Bashe targets reflects empirical data showing that ransomware groups disproportionately target affluent, English-speaking nations. The United States, Canada, the United Kingdom, and Australia are highly overrepresented relative to their economic scale.  

However, Bashe also exhibits a strong opportunistic focus globally, successfully targeting sovereign entities in Brazil, the Philippines, Vietnam, and the UAE. This wide distribution indicates that the group's Initial Access Brokers actively exploit vulnerable VPNs and RDPs globally, capitalizing on geopolitical and regional digitization vulnerabilities.  



Attack Lifecycle


A complete Bashe ransomware attack follows a meticulous, multi-staged extortion chain:

  1. Initial Compromise: Gaining network access via compromised credentials or vulnerability exploitation.

  2. Internal Reconnaissance & Privilege Escalation: Navigating the network, dumping administrative credentials.

  3. Lateral Movement & Defense Evasion: Disabling EDR solutions and propagating the payload via SMB/GPO.

  4. Data Collection & Exfiltration: Funneling sensitive files out of the network to attacker-controlled cloud storage.

  5. Encryption: Deploying the LockBit 3.0 payload to lock all remaining files.

  6. Ransom Negotiation: Demanding payment on the Tor-based DLS, threatening Double Extortion. (In some scenarios, DDoS attacks are added to create Triple Extortion pressure).


Bashe Ransomware Group: Dark Web Data Leak Case Study | Securedmonk


Initial Access Techniques


The Bashe ransomware TTPs for initial access are heavily reliant on the affiliate executing the intrusion. Common entry vectors observed across the operation include:

  • Phishing Emails: Spear-phishing campaigns delivering malicious payloads or harvesting corporate credentials.  

  • Exposed RDP & VPNs: Exploiting vulnerable, internet-facing Remote Desktop Protocol services.  

  • Initial Access Brokers (IABs): Purchasing pre-established network footholds directly from dark web marketplaces to bypass the reconnaissance phase entirely.  



Technical Analysis


The Bashe ransomware malware capability is directly attributed to the leaked LockBit 3.0 (LockBit Black) builder. A technical examination reveals an enterprise-grade threat:  

  • Execution & Evasion: The payload requires a 32-character hexadecimal password (e.g., -pass [hash]) to unpack the executable in memory, actively thwarting dynamic analysis and automated sandboxes.  

  • Encryption Routines: Bashe ransomware encryption utilizes an intermittent encryption model employing AES-256 for file data and RSA-2048 to secure the symmetric keys, optimizing for devastating speed.  

  • System Modification & Backup Deletion: The malware systematically eliminates recovery options using vssadmin.exe delete shadows /all /quiet and wmic shadowcopy delete. It also suppresses recovery modes using bcdedit and can force the machine into Safe Mode (-safe) to encrypt files without EDR interference.  

  • Ransom Note Analysis: Once encrypted, the payload drops customized [random_string]_README.txt files across directories and modifies the desktop wallpaper, directing the victim to their negotiation portal.  



MITRE ATT&CK Mapping


The observed behaviors of Bashe can be mapped to the MITRE ATT&CK framework:

  • Initial Access: Valid Accounts (T1078), Exploit Public-Facing Application (T1190)

  • Execution & Persistence: Service Execution (T1569.002), Scheduled Task/Job (T1053)

  • Privilege Escalation & Defense Evasion: Impair Defenses (T1562.001 - Disabling Defender), Obfuscated Files (T1027.002 - Password-protected execution)

  • Discovery & Lateral Movement: Lateral Tool Transfer (T1570), Remote Services (T1021 - SMB/Admin Shares)

  • Collection & Exfiltration: Exfiltration over Web Service (T1567.002 - using Rclone/MEGASync)

  • Impact: Data Encrypted for Impact (T1486), Inhibit System Recovery (T1490 - shadow copy deletion)



Indicators of Compromise and Detection Opportunities


SOC analysts must prioritize behavioral indicators over static hashes, as the LockBit builder generates unique Bashe ransomware IOC

 markers for each compilation.

Bashe ransomware indicators of compromise include:

  • Host-Based: Execution of commands terminating backup services (vssadmin, wmic, wbadmin, bcdedit). Anomalous use of the ICMLuaUtil COM interface for UAC bypass.  

  • Network-Based: Tor browser installation, unusual outbound traffic spikes to cloud storage domains (e.g., MEGA, Rclone user-agents) during off-hours.  

  • Identity-Based: Impossible travel alerts, sudden privilege escalation on service accounts.



Detection Engineering and SIEM Use Cases


Security operations teams should configure SIEM platforms (Splunk, Microsoft Sentinel, Elastic Security) to detect precursor behaviors:

  • KQL/SPL Hunts: Query for process creation events (Event ID 4688) containing vssadmin delete shadows or bcdedit /set {default} safeboot.  

  • Detection Philosophy: Rather than relying purely on YARA rules for a highly obfuscated binary, detections must focus on the behavior of inhibiting system recovery and high-volume data exfiltration, alerting defenders before the encryption routine fully detonates.



Incident Response Considerations


If an organization suspects an ongoing attack, immediate action is required.

  • Containment: Isolate affected segments, but preserve the environment for forensic investigation. Do not immediately wipe or rebuild systems.  

  • Identification & Eradication: Determine how access was obtained (e.g., exposed VPN), remove attacker persistence mechanisms, and issue legal takedown notices where possible.  

  • Bashe ransomware negotiation: Involve professional incident responders, legal counsel, and negotiators before communicating via the DLS. Understand that paying the ransom funds further attacks and provides no guarantee of data deletion or recovery.



Defensive Recommendations


Practical defensive guidance requires a layered approach:

  • Identity Security & PAM: Enforce Multi-Factor Authentication (MFA) on all external gateways and limit administrative privileges to disrupt lateral movement.

  • Endpoint Detection and Response (EDR): Deploy tamper-resistant EDR with anti-ransomware rollback capabilities to block unauthorized process creation and registry modifications.

  • Network Segmentation: Strictly segment IT networks from OT/SCADA systems to prevent lateral ransomware spread into physical operational environments.  

  • Immutable Backups: Maintain isolated, offline, and immutable backups that cannot be purged via compromised domain administrator credentials.



Conclusion


The Dark web ransomware group known as Bashe provides a stark reminder of the realities of the modern threat landscape. By leveraging leaked, military-grade encryption builders and psychological marketing, Bashe successfully transitioned from a performative copycat into a genuine threat against global critical infrastructure. Their operations confirm that leak-site extortion and data theft have permanently replaced simple encryption as the primary leverage points in cyber extortion. Organizations that invest in comprehensive visibility, identity protection, and proactive threat hunting will be significantly better positioned to detect and eradicate these threats before they culminate in catastrophic business disruption.

Comments


bottom of page