Ransomware Intelligence

apt73/bashe

Ransomware group profile

49Victims
Czech RepublicSource country
65Impact score
Also Known As
Bashe
APT73
Apt 73

Description

Eraleign is a high-profile ransomware group that specializes in advanced cyberattacks targeting large organizations for maximum financial gain. Known for their sophisticated encryption methods and double extortion tactics, they employ custom-built malware to infiltrate networks and have shifted their focus towards critical infrastructure and supply chain attacks.

Key insights

  • Utilizes rapid encryption methods and multi-stage infection chains.
  • Targets multiple sectors, especially critical infrastructure and healthcare.
  • Employs double extortion tactics by threatening to leak stolen data.
  • Gains initial access via phishing campaigns and known vulnerabilities.
  • Demonstrates a trend towards leveraging REvil's toolkit and tactics.

Threat Level & Status Breakdown

For apt73/bashe · Based on incidents in selected period

3.4threat level
Aggressiveness8/ 10
Lethality0/ 10
Criticality2/ 10

Status Breakdown

Claimed100.0%49
First seenJan 2026
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 23, 2026

Recent activity

Monthly attack count for apt73/bashe in the selected period

49Total attacks
17peak in Mar
8.2avg / month
↑ 3 vs first month
JanFebMarAprMayJun05101520

Intelligence

IOCs, YARA/Sigma rules, and related families for apt73/bashe

  1. ns2.eraleignews.com
  2. basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion
  3. ns3.eraleignews.com
  4. basheqtvzqwz4vp6ks5lm2ocq7i6tozqgf6vjcasj4ezmsy4bkpshhyd.onion
  5. fleqwmg7xnanypt5km2m75l72q7nlcvlp2m4sdmgjxorsn6tb3zyp3qd.onion
  6. qcgv5tfer4f46ns6ohh72zeyyh5uavoiybypzpt3lmwk5ecyqykptgqd.onion
  7. eraleignews.com
  8. bashe4aec32kr6zbifwd5x6xgjsmhg4tbowrbx4pneqhc5mqooyifpid.onion
  9. wn6vonooq6fggjdgyocp7bioykmfjket7sbp47cwhgubvowwd7ws5pyd.onion
  10. ns4.eraleignews.com
  11. ns1.eraleignews.com
View full IOC feed11 total

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for apt73/bashe

Other

T1486

T1486

T1490

T1490

T1562

T1562

T1040

T1040

T1071

T1071

T1078

T1078

T1059

T1059

T1021

T1021

T1021.001

T1021.001

T1547

T1547

Victims(49)

CompanyDomainCountryIndustryStatusDiscovered
kliknklik.comkliknklik.comID IndonesiaRetail & E-Commerce
Claimed
2 days ago
gov.brgov.brBR BrazilGovernment & Defense
Claimed
2 days ago
viennaairport.comviennaairport.comAT AustriaTransportation
Claimed
2 days ago
smarty.arpinet.amsmarty.arpinet.amAM ArmeniaTechnology
Claimed
22 days ago
elections.mia.gov.am from WOLVES OF TURANelections.mia.gov.amAM ArmeniaGovernment & Defense
Claimed
23 days ago
tkgm.gov.trtkgm.gov.trTR TurkeyGovernment & Defense
Claimed
about 1 month ago
minsa.com.mxminsa.com.mxMX MexicoManufacturing
Claimed
about 1 month ago
tvnmedia.comtvnmedia.comPA PanamaTechnology
Claimed
about 1 month ago
alkaloid.com.mkalkaloid.com.mkMK North MacedoniaHealthcare
Claimed
about 1 month ago
narit.or.thnarit.or.thTH ThailandGovernment & Defense
Claimed
about 1 month ago
grupopetersen.com.argrupopetersen.com.arAR ArgentinaFinancial Services
Claimed
about 1 month ago
ungererandcompany.comungererandcompany.comUS United StatesManufacturing
Claimed
about 1 month ago
medikaplaza.comID IndonesiaManufacturing
Claimed
about 2 months ago
jgpetrucci.comUS United StatesProfessional Services
Claimed
about 2 months ago
providentgh.comprovidentgh.comGH GhanaFinancial Services
Claimed
about 2 months ago
grupo-principal.comMX MexicoRetail & E-Commerce
Claimed
about 2 months ago
cofaco.comPE PeruRetail & E-Commerce
Claimed
about 2 months ago
dunav.comRS SerbiaFinancial Services
Claimed
about 2 months ago
algosaibi-gtb.comSA Saudi ArabiaHealthcare
Claimed
about 2 months ago
alx-pc.comEG EgyptEnergy & Utilities
Claimed
about 2 months ago

Page 1 of 3