Ransomware Intelligence

apt73/bashe Ransomware Group

Ransomware group profile

17Victims
Czech RepublicSource country
65Impact score
Also Known As
Bashe
APT73
Apt 73

Description

Eraleign is a high-profile ransomware group that specializes in advanced cyberattacks targeting large organizations for maximum financial gain. Known for their sophisticated encryption methods and double extortion tactics, they employ custom-built malware to infiltrate networks and have shifted their focus towards critical infrastructure and supply chain attacks.

Key insights

  • Utilizes rapid encryption methods and multi-stage infection chains.
  • Targets multiple sectors, especially critical infrastructure and healthcare.
  • Employs double extortion tactics by threatening to leak stolen data.
  • Gains initial access via phishing campaigns and known vulnerabilities.
  • Demonstrates a trend towards leveraging REvil's toolkit and tactics.

Threat Level & Status Breakdown

For apt73/bashe · Based on incidents in selected period

2.1threat level
Aggressiveness4.3/ 10
Lethality0/ 10
Criticality2/ 10

Status Breakdown

Claimed100.0%17
First seenMar 2026
Last seenJul 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedAug 7, 2026

Recent activity

Monthly attack count for apt73/bashe in the selected period

17Total attacks
7peak in Mar
3.4avg / month
↓ 6 vs first month
MarAprMayJunJul02468

Intelligence

IOCs, YARA/Sigma rules, and related families for apt73/bashe

  1. eraleignews.com
  2. ns1.eraleignews.com
  3. ns2.eraleignews.com
  4. ns3.eraleignews.com
  5. ns4.eraleignews.com
  6. bashe4aec32kr6zbifwd5x6xgjsmhg4tbowrbx4pneqhc5mqooyifpid.onion
  7. basheqtvzqwz4vp6ks5lm2ocq7i6tozqgf6vjcasj4ezmsy4bkpshhyd.onion
  8. qcgv5tfer4f46ns6ohh72zeyyh5uavoiybypzpt3lmwk5ecyqykptgqd.onion
  9. wn6vonooq6fggjdgyocp7bioykmfjket7sbp47cwhgubvowwd7ws5pyd.onion
  10. fleqwmg7xnanypt5km2m75l72q7nlcvlp2m4sdmgjxorsn6tb3zyp3qd.onion
  11. basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion
View full IOC feed11 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for apt73/bashe

Other

T1486

T1486

T1490

T1490

T1562

T1562

T1040

T1040

T1071

T1071

T1078

T1078

T1059

T1059

T1021

T1021

T1021.001

T1021.001

T1547

T1547

Victims(17)

SpainHospitalityholidaypalace.com
Claimed
about 1 month ago
IndonesiaRetail & E-Commercekliknklik.com
Claimed
about 2 months ago
ArmeniaGovernment & Defenseelections.mia.gov.am
Claimed
2 months ago
ThailandGovernment & Defensenarit.or.th
Claimed
3 months ago
GhanaFinancial Servicesprovidentgh.com
Claimed
3 months ago
SerbiaFinancial Servicesdunav.com
Claimed
3 months ago
EgyptEnergy & Utilitiesalx-pc.com
Claimed
3 months ago
Saudi ArabiaHealthcarearrawdah.org.sa
Claimed
3 months ago
United StatesRetail & E-Commercephb.com
Claimed
4 months ago
PortugalEnergy & Utilitiesasunim.co
Claimed
4 months ago
MoroccoProfessional Servicesires.ma
Claimed
4 months ago
BelgiumManufacturingvanheyghenstaal.be
Claimed
5 months ago
BelgiumHealthcareisosl.be
Claimed
5 months ago
United Arab EmiratesGovernment & Defensemoccae.gov.ae
Claimed
5 months ago
PalestineEnergy & Utilitiesgedco.ps
Claimed
5 months ago
MoroccoTechnologyhaca.ma
Claimed
5 months ago
ChileTechnologyseit.cl
Claimed
5 months ago