logo

Unmasking Media-Hungry Ransomware Groups: Bashe (APT73)

ID: 2431b08f-faf1-555b-b12c-bd22e2b5e96d

STIX ID: report--2431b08f-faf1-555b-b12c-bd22e2b5e96d

Feed Name: CloudSEK Blog

Threat Score
50/100

Date Published: 2025-01-29

Date Updated: 2026-05-13

...
...

This report assesses Bashe (self-styled APT73/eraleign) as a recently active ransomware actor whose public data leak claims across multiple targets are largely fraudulent—reposting or curating old leaks and combolists—while warning that media exposure could nonetheless attract affiliates and increase future operational risk; it includes timelines of alleged leaks, analysis showing reused data, impact assessment, and recommendations to validate claims and improve monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.