MO
Ransomware Victim Manufacturing

Moraviakov s.r.o.

Ransomware attack by 8base Β· Disclosed January 14, 2025 Β· πŸ‡¨πŸ‡Ώ Czech Republic

cts-moravia.webnode.cz

Date Disclosed
Jan 14, 2025
2025
Threat Group
8base
177 total victims
Industry
Manufacturing

ThreatAI Analysis

Compiled from this incident record and the threat intelligence profile for 8base. Figures and technique mappings are quoted from the source data, not inferred.

About the 8base group

The 8base Ransomware group made its first appearance in early March 2022, remaining somewhat quiet after the attacks. This group operates like other ransomware actors, engaging in double extortion. However, in mid-May and June 2023, the ransomware operation saw a spike in activity against organizations from various sectors, listing 131 organizations in just 3 months. The 8base data leak site was created and made available in March 2023, claiming honesty and simplicity in its discourse. VMware published a report on 8base, drawing some similarities with the ransomware group `RansomHouse`, pointing out resemblances such as the website used by 8base and the ransom notes presented in its attacks. Interestingly, the 8base Ransomware group does not have its own ransomware developed by the group. Instead, the actors took advantage of other leaked ransomware builders to customize the ransom note 8base has listed 455 victims since April 2022.

How 8base is documented to operate

Scheduled Task/Job T1053 Execution Persistence

Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, provided the proper authentication is met (ex: RPC and file and printer sharing in Windows environments). Scheduling a task on a remote system typically may require being a member of an admin or otherwise privileged group on the remote system. Adversaries may use task scheduling to execute programs at system startup or on a scheduled basis for persistence.

Mitigations: Operating System Configuration, User Account Management, Restrict File and Directory Permissions, Privileged Account Management, Audit

MITRE ATT&CK reference β†’
Command and Scripting Interpreter T1059 Execution

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell. There are also cross-platform interpreters such as Python, as well as those commonly associated with client applications such as JavaScript and Visual Basic.

Mitigations: Restrict Web-Based Content, Limit Software Installation, Execution Prevention, Code Signing, Behavior Prevention on Endpoint, Privileged Account Management

MITRE ATT&CK reference β†’
Shared Modules T1129 Execution

Adversaries may execute malicious payloads via loading shared modules. Shared modules are executable files that are loaded into processes to provide access to reusable code, such as specific custom functions or invoking OS API functions (i.e., Native API). Adversaries may use this functionality as a way to execute arbitrary payloads on a victim system. For example, adversaries can modularize functionality of their malware into shared objects that perform various functions such as managing C2 network communications or execution of specific actions on objective. The Linux & macOS module loader can load and execute shared objects from arbitrary local paths.

Mitigations: Execution Prevention

MITRE ATT&CK reference β†’
Boot or Logon Autostart Execution T1547 Persistence Privilege Escalation

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon. These mechanisms may include automatically executing programs that are placed in specially designated directories or are referenced by repositories that store configuration information, such as the Windows Registry. An adversary may achieve the same goal by modifying or extending features of the kernel.

MITRE ATT&CK reference β†’
Token Impersonation/Theft T1134.001 Stealth Privilege Escalation

Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using DuplicateToken or DuplicateTokenEx. The token can then be used with ImpersonateLoggedOnUser to allow the calling thread to impersonate a logged on user's security context, or with SetThreadToken to assign the impersonated token to a thread. An adversary may perform Token Impersonation/Theft when they have a specific, existing process they want to assign the duplicated token to. For example, this may be useful for when the target user has a non-network logon session on the system.

Mitigations: User Account Management, Privileged Account Management

MITRE ATT&CK reference β†’

MITRE ATT&CK techniques attributed to 8base across its recorded activity, not a finding about how Moraviakov s.r.o. was reached.

Incident Analysis

Moraviakov s.r.o. was targeted by 8base ransomware, one of the most active ransomware groups in our database with 177 confirmed victims globally. The attack was disclosed on January 14, 2025, when Moraviakov s.r.o. appeared on the group's dark web leak site.

Moraviakov s.r.o. is based in Czech Republic , operating in the Manufacturing sector. Czech Republic ranks #33 globally for ransomware attacks, with 87 victims in our database.

Sector context: Manufacturing companies are frequently targeted because production downtime directly translates to financial loss. Ransomware operators exploit this time-sensitivity to demand higher ransoms and faster payment.

8base typically employs a double extortion model: first exfiltrating sensitive data from the victim's systems, then deploying ransomware to encrypt files. Victims face two simultaneous threats β€” paying to restore access and paying to prevent publication of stolen data. The group's leak site publishes victim names and exfiltrated data as leverage.

Data source: This incident record is sourced from public ransomware group leak site disclosures aggregated via the ransomware.live API. Disclosure date reflects when the victim was published on the leak site, which may differ from the initial date of compromise. This platform does not publish or link to stolen data. Last data update: Sep 5, 2026 20:00 UTC.

Frequently Asked Questions

Was Moraviakov s.r.o. attacked by ransomware?

Yes. Moraviakov s.r.o. was listed as a victim of the 8base ransomware group on January 14, 2025. The organisation is based in Czech Republic and operates in the Manufacturing sector. The disclosure appeared on the group's dark web leak site.

Which ransomware group attacked Moraviakov s.r.o.?

Moraviakov s.r.o. was attacked by 8base ransomware. 8base is one of the most active ransomware groups, having claimed 177 victims globally. The group typically employs a double-extortion model: encrypting the victim's files and threatening to publish stolen data.

When did the Moraviakov s.r.o. ransomware attack occur?

The ransomware attack on Moraviakov s.r.o. was disclosed on January 14, 2025. This date reflects when the victim was published on the threat group's leak site, which may differ from the actual date of initial compromise.

What data was stolen in the Moraviakov s.r.o. ransomware attack?

The specific data stolen from Moraviakov s.r.o. has not been independently verified by this platform. Ransomware groups typically exfiltrate data before encrypting systems and use the threat of publication to pressure victims. As a Manufacturing organisation, Moraviakov s.r.o. likely held sensitive business data, client information, and operational records.

How can organisations protect against 8base attacks?

To defend against 8base and similar threat actors, organisations should: maintain regular offline backups tested for restoration; implement network segmentation to limit lateral movement; deploy multi-factor authentication on all remote access; use endpoint detection and response (EDR) tools; conduct regular phishing and security awareness training; and monitor threat intelligence feeds for indicators of compromise (IOCs) associated with active groups.