Ransomware Group:  
Apt73
 / 
Bashe



Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


Sites | Activity | Worldmap | Victims (69)

A new ransomware group is said to have emerged in mid-April 2024, under the name 'APT73.' It's worth noting that the group reportedly self-proclaimed as an APT, which stands for 'Advanced Persistent Threat' in the cybersecurity field.

According to research, much of the available information about the aforementioned group came from another ransomware group known as LockBit.
Source: https://github.com/crocodyli/ThreatActors-TTPs


Sites

Favicon Title Available Last Visit FQDN Screenshot
APT73 🔴 2024-04-24 12:44:54.955436 eraleignews.com N/A
APT73 🔴 2025-01-11 19:17:19.228163 wn6vonooq6fggjdgyocp7bioykmfjket7sbp47cwhgubvowwd7ws5pyd.onion N/A
APT73 🔴 2025-01-11 19:17:36.450145 fleqwmg7xnanypt5km2m75l72q7nlcvlp2m4sdmgjxorsn6tb3zyp3qd.onion N/A
APT73 🔴 2025-01-11 19:17:45.430679 apt73grpjgjwykrenq7vnjejue76vosdzptdvmonv7vyqnsyokrw57ad.onion N/A
🔴 2025-01-18 00:45:14.617688 bashe4aec32kr6zbifwd5x6xgjsmhg4tbowrbx4pneqhc5mqooyifpid.onion N/A
BASHE 🔴 2025-01-18 00:45:20.269549 basheqtvzqwz4vp6ks5lm2ocq7i6tozqgf6vjcasj4ezmsy4bkpshhyd.onion N/A
BASHE 🔴 2025-01-18 00:45:28.284319 basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion N/A
BASHE 🔴 2025-01-18 00:45:33.103419 basherykagbxoaiaxkgqhmhd5gbmedwb3di4ig3ouovziagosv4n77qd.onion N/A
BASHE 🔴 2025-01-18 00:45:37.052819 basherykagbxoaiaxkgqhmhd5gbmedwb3di4ig3ouovziagosv4n77qd.onion N/A
BASHE 🔴 2025-01-18 00:45:44.086104 bashete63b3gcijfofpw6fmn3rwnmyi5aclp55n6awcfbexivexbhyad.onion N/A
BASHE 🔴 2025-01-18 00:45:49.116433 bashex7mokreyoxl6wlswxl4foi7okgs7or7aergnuiockuoq35yt3ad.onion N/A

Activity over time

Worldmap

69 Victims

FR flag

fol-23.fr 

Company logo
Ransomware Group:

Discovery Date: 2025-01-17 16:19

Sector: Not Found
The Federation of Secular Works of the Creuse brings together each year between 230 and 250 assoc...

Victim:   |  Group: 
MT flag

betclic.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-15 18:20

Online Betting - "LastName","Address","City","State","ZipCode","Country","Email","Phone"

Victim:   |  Group: 
ZA flag

pnp.co.za 

Company logo
Ransomware Group:

Discovery Date: 2025-01-09 16:38

Pick n Pay Group Ltd. is a South African retailer. It operates three brands – Pick n Pay, Boxer...

Victim:   |  Group: 
IN flag

federalbank.co.in (PART1) 

Company logo
Ransomware Group:

Discovery Date: 2024-12-24 12:09

Sector: Financial
Sharing a little part with you. Indian bank. Full amount - 637895 lines CUSTOMERNAME CUST_ID_N FNAME DOB PAN_NO MNAME LNAME AGE SEX FATHERNAME SPOU...

Victim:   |  Group: 
BR flag

n4telecom.com.br 

Company logo
Ransomware Group:

Discovery Date: 2024-12-23 17:41

Our mission - Provide telecommunications solutions with quality and humane service, connecting people and growing businesses.

Victim:   |  Group: 
ID flag

linebank.co.id 

Company logo
Ransomware Group:

Discovery Date: 2024-12-23 17:38

Sector: Financial
Indonesia Digital Banking personal info

Victim:   |  Group: 
IN flag

federalbank.co.in 

Company logo
Ransomware Group:

Discovery Date: 2024-12-20 04:09

Sector: Financial
Indian bank. 637895 lines CUSTOMERNAME CUST_ID_N FNAME DOB PAN_NO MNAME LNAME AGE SEX FATHERNAME SPOUSENAME DRIVINGLICENSENO PASSPORT...

Victim:   |  Group: 
ID flag

bri.co.id 

Company logo
Ransomware Group:

Discovery Date: 2024-12-18 11:57

Sector: Financial
Bank Rakyat Indonesia (BRI) is one of the largest commercial banks in Indonesia that always prioritizes customer satisfaction. Personal data, clien...

Victim:   |  Group: 
ES flag

www.prixet.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-16 17:15

Sector: Technology
We are a technology company based in Europe and the Caribbean. We are dedicated to data creation through hotspots. We create the different hotspots...

Victim:   |  Group: 
BO flag

www.minerasancristobal.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-11 16:38

Sector: Not Found
Minerals & Mining. financial docs, internal docs, personal docs.

Victim:   |  Group: 
US flag

leadboxhq.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-10 16:12

Sector: Technology
Advertising & Marketing / clients' data / id index score source closed_at company: id name uuid contact id name phone uuid created_at ...

Victim:   |  Group: 
BR flag

melhorcompraclube.com.br 

Company logo
Ransomware Group:

Discovery Date: 2024-12-09 16:50

The Best Purchase Club is a cashback platform that was born as a product of Telepequisa, a potiquis company with almost 30 years of experience in t...

Victim:   |  Group: 
US flag

www.bms.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-09 15:08

Sector: Healthcare
Pharmaceutical company. personal data - 302 lines

Victim:   |  Group: 
MR flag

bankily.mr 

Company logo
Ransomware Group:

Discovery Date: 2024-12-09 15:05

Sector: Financial
The BANKILY product is a mobile banking product from Banque Populaire de Mauritanie. Employee names and data, including the admin’s username, cu...

Victim:   |  Group: 
AZ flag

azpay.me 

Company logo
Ransomware Group:

Discovery Date: 2024-12-05 18:16

Sector: Financial
Azape began its journey in 2018 by developing customized projects for various market segments, with its focus on developing solutions for intermedi...

Victim:   |  Group: 
PL flag

www.aliorbank.pl 

Company logo
Ransomware Group:

Discovery Date: 2024-12-05 11:48

Sector: Financial
Polish bank. Financial docs, internal docs. 0,06 GB of data.

Victim:   |  Group: 
US flag

www.certifiedinfosec.com 

Company logo
Ransomware Group:

Discovery Date: 2024-12-04 12:45

Sector: Technology
Certified Information Security is a registered trade name for Certified Tech Trainers (CTT) (D-U-N-S# 010573009) (CAGE code: 3FKS0), a corporation ...

Victim:   |  Group: 
BR flag

www.siapenet.gov.br 

Company logo
Ransomware Group:

Discovery Date: 2024-12-03 18:15

Sector: Government
Today, SIAPE processes the remuneration of civil servants, regulated both by the uniform federal legal regime (Law 8,112/90) and by the CLT and oth...

Victim:   |  Group: 
IT flag

www.sansirostadium.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-30 11:57

Italian stadium. Total machines accesses, main stations, footballers' personal data, UEFA personal contact data, big screens control machines. 1 ...

Victim:   |  Group: 
AT flag

www.polleninformation.at 

Company logo
Ransomware Group:

Discovery Date: 2024-11-27 20:41

Sector: Healthcare
Pollen situation informational site. Personal info + Pass. 22140 lines

Victim:   |  Group: 
BR flag

www.sella.eng.br 

Company logo
Ransomware Group:

Discovery Date: 2024-11-26 18:04

mentoring programs for managers. Internal and personal docs. 0.3 GB

Victim:   |  Group: 
RO flag

www.netromsoftware.ro 

Company logo
Ransomware Group:

Discovery Date: 2024-11-25 16:35

Sector: Technology
Romanian software development company. Export CRM

Victim:   |  Group: 
PE flag

www.protectasecurity.pe 

Company logo
Ransomware Group:

Discovery Date: 2024-11-23 16:52
Estimated Attack Date: 2024-11-18

Protecta Security provides insurance, microfinance and financial services. Internal docs, financial docs, personal info, customers' personal info. ...

Victim:   |  Group: 
AT flag

rao.hr 

Company logo
Ransomware Group:

Discovery Date: 2024-11-23 16:49
Estimated Attack Date: 2024-11-20

Sector: Technology
RAO d.o.o. is a member of the Best in Parking AG group, Austria. With more than a quarter of a century of dedication and professional work, it is a...

Victim:   |  Group: 
FR flag

sfr.fr 

Company logo
Ransomware Group:

Discovery Date: 2024-11-23 16:46
Estimated Attack Date: 2024-07-12

SFR is a French telecommunications company. It is both the second oldest mobile network operator and the second largest telecommunications company ...

Victim:   |  Group: 
PL flag

gureco.pl 

Company logo
Ransomware Group:

Discovery Date: 2024-11-23 16:43

Gureko GURECO Sp. z o.o. is a private company. We began our activity on 10 March 2008 based on an entry in the Register of Economic Activities of t...

Victim:   |  Group: 
IN flag

lgpunjab.gov.in 

Company logo
Ransomware Group:

Discovery Date: 2024-11-23 16:40

Sector: Government
GOVERNMENT OF PUNJAB Backup CRM, 0.2 GB

Victim:   |  Group: 
CH flag

nanolive.ch 2.0 

Company logo
Ransomware Group:

Discovery Date: 2024-11-13 11:40

Sector: Healthcare
Nanolive’s label-free live cell imaging and analysis platforms, consumables and services are built on technology that is 100% non-invasive, thus ...

Victim:   |  Group: 
BR flag

emefarmario.com.br 

Company logo
Ransomware Group:

Discovery Date: 2024-11-09 12:10

We are the Emefarma Group! A leading pharmaceutical distribution company that grew with the purpose of bringing health and well-being to people's l...

Victim:   |  Group: 
US flag

liftkits4less.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-08 16:18

LIFTKITS4LESS.COM is the largest online seller of suspension lift kit systems. clients' data: ID,Name,Email,Group,Phone,ZIP,Country,State/Province...

Victim:   |  Group: 
FR flag

www.lamaisonducitron.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-08 16:15

Lemon product store.

Victim:   |  Group: 
CH flag

www.baldinger-ag.ch 

Company logo
Ransomware Group:

Discovery Date: 2024-11-08 16:12

Since 1970, Baldinger Fahrzeugbau has stood for continuous innovation and the highest quality. We are still the leading manufacturer of light comme...

Victim:   |  Group: 
NL flag

www.assurified.com 

Company logo
Ransomware Group:

Discovery Date: 2024-11-08 10:08

Sector: Financial
Assurified revolutionizes risk management for multifamily real estate. Our AI-powered solutions and deep expertise in Total Cost of Risk (TCOR) opt...

Victim:   |  Group: 
UY flag

www.botiga.com.uy 

Company logo
Ransomware Group:

Discovery Date: 2024-11-08 10:05

An online store where you will find everything you need and want for you and your family. We have over 10,000 products to complement every stage o...

Victim:   |  Group: 
NL flag

www.trinitesolutions.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-29 15:49

Sector: Technology
Trinite Solutions was established in 2003. Its mission is to develop, market and implement business software solutions for all sizes of enterprise....

Victim:   |  Group: 
DE flag

www.scopeset.de 

Company logo
Ransomware Group:

Discovery Date: 2024-10-29 15:46

Sector: Technology
We offer support services for all our developed solutions and tools with an emphasize on direct access to our experts and quick turn around times f...

Victim:   |  Group: 
ID flag

sokkakreatif.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-29 15:43

PT. Sokka Kreatif Teknologi was established in 2017, and is a subsidiary of PT. Persada Inti Utama whose main businesses include telecommunications...

Victim:   |  Group: 
FR flag

www.legilog.fr 

Company logo
Ransomware Group:

Discovery Date: 2024-10-29 15:40
Estimated Attack Date: 2024-10-08

Management software for culture, businesses, religion and bishoprics. 10 GBs crm systems / export files and backups / personal data

Victim:   |  Group: 
US flag

pkaufmann.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 15:32

P/Kaufmann Fabrics is the premier home furnishings textile converter, having supplied our customers with expertly-crafted designs for over sixty fi...

Victim:   |  Group: 
GB flag

modplan.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 15:31

For over 50 years, Modplan has been manufacturing and supplying leading-edge products to our installing partners for the fenestration market. Funda...

Victim:   |  Group: 
US flag

hpecds.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 15:30

Sector: Technology
CDS, a Hewlett Packard Enterprise company CDS is a wholly owned subsidiary of Hewlett Packard Enterprise and although an integral part of delivery...

Victim:   |  Group: 
CA flag

thompsoncreek.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 14:03
Estimated Attack Date: 2024-10-23

Thompson Creek® Window Company is the Mid-Atlantic region’s premier home improvement replacement products company. We have been customizing and ...

Victim:   |  Group: 
US flag

www.northernsafety.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 14:02
Estimated Attack Date: 2024-10-23

Northern Safety Co., Inc. operates as a personal safety equipment distributor company. The Company offers disposable respirators, earplugs, first a...

Victim:   |  Group: 
US flag

mgfsourcing.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 14:01
Estimated Attack Date: 2024-10-23

MGF Sourcing is an independent US-led global sourcing company founded in 1970. We focus on US-based specialty apparel retailers and, with our stron...

Victim:   |  Group: 
AU flag

appen.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 14:00
Estimated Attack Date: 2024-10-17

Sector: Technology
Registered user base of the appen.com platform (AI training company). 5 887 922 lines email addresses, employers, IP addresses, names, passwords,...

Victim:   |  Group: 
IN flag

filmai.in 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 13:57
Estimated Attack Date: 2024-10-17

Sector: Not Found
Indian Movie Streaming Service Data email addresses, passwords, usernames 645 000 lines

Victim:   |  Group: 
US flag

drizly.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 13:54
Estimated Attack Date: 2024-10-17

Databases of users of the E-Commerce platform "Drizly" (a platform for the sale of alcoholic beverages). 2 479 145 lines. dates of birth, device in...

Victim:   |  Group: 
US flag

robinhood.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 13:51
Estimated Attack Date: 2024-10-17

Sector: Financial
Robinhood Broker Clients' Data. 7 732 244 lines of emails

Victim:   |  Group: 
GB flag

thebeautyclick.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 13:48
Estimated Attack Date: 2024-10-21

The Beauty Click was founded in April 2018 by Chantelle Bass. A website that has a platform for both the beauty and hair specialists themselves a...

Victim:   |  Group: 
GB flag

trans-logik.com 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 13:45
Estimated Attack Date: 2024-10-21

Transense Surface Acoustic Wave or SAW sensor technology is proven to deliver accurate, real-time measurement of torque, temperature, force and pre...

Victim:   |  Group: 
GB flag

www.talonsolutions.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 13:42
Estimated Attack Date: 2024-10-21

Sector: Technology
Talon Solutions Ltd was formed by Vince Cluderay in 2002 for the purpose of selling document management and database solutions into the UK construc...

Victim:   |  Group: 
GB flag

Sandro Forte Financial Support 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 12:24
Estimated Attack Date: 2024-10-21

Sector: Financial
Sandro Forte is a personal growth and development speaker, and one of the most respected and successful entrepreneurs in his profession, motivating...

Victim:   |  Group: 
US flag

Susan Fischgrund 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 12:23
Estimated Attack Date: 2024-10-21

Sector: Not Found
Language therapist Personal info + documents 2 GB

Victim:   |  Group: 
CH flag

nanolive.ch 

Company logo
Ransomware Group:

Discovery Date: 2024-10-24 12:22
Estimated Attack Date: 2024-10-21

Sector: Healthcare
Nanolive’s label-free live cell imaging and analysis platforms, consumables and services are built on technology that is 100% non-invasive, thus ...

Victim:   |  Group: 
GB flag

rylandpeters.com 

Company logo
Ransomware Group:

Discovery Date: 2024-08-22 15:06

Ryland Peters & Small and CICO Books is an independent, illustrated publisher creating beautifully produced books in the areas of interior design, ...

Victim:   |  Group: 
GB flag

www.pindrophearing.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-08-21 15:18

Sector: Healthcare
We’re specialists in the diagnosis and treatment of hearing conditions, but just as important is our understanding that hearing loss can make peo...

Victim:   |  Group: 
GB flag

globacap.com 

Company logo
Ransomware Group:

Discovery Date: 2024-08-21 10:09

Sector: Financial
Globacap is an innovative private markets ecosystem that allows you to compress manual workflow processes, streamlining the execution of transactio...

Victim:   |  Group: 
GB flag

www.gannons.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-06-14 16:27

Gannons Commercial Law Limited Catherine Gannon, then a tax solicitor at a large US law firm, looks out from their ivory tower and spots a gap in ...

Victim:   |  Group: 
CH flag

Borrer Executive Search 

Company logo
Ransomware Group:

Discovery Date: 2024-06-13 17:37

Borrer Executive Search is an AESC accredited boutique search and selection firm based in Lausanne, Switzerland. internal documents, agreements ...

Victim:   |  Group: 
GB flag

www.bigalsfoodservice.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-06-13 17:36

Our foodservice roots trace all the way back to a butchers shop in Dublin city centre in 1966. Kepak Foodservice specialise in creating innovative,...

Victim:   |  Group: 
GB flag

apex.uk.net 

Company logo
Ransomware Group:

Discovery Date: 2024-06-12 06:43

Apex Engineering Service has established itself as a leading supplier of technical services to the construction industry worldwide. Passwords, int...

Victim:   |  Group: 
HK flag

AlphaNovaCapital 

Company logo
Ransomware Group:

Discovery Date: 2024-06-12 06:41

Sector: Financial
Private limited Company 272KB

Victim:   |  Group: 
GB flag

AMI Global Assistance 

Company logo
Ransomware Group:

Discovery Date: 2024-06-12 06:40

Sector: Healthcare
Your trusted partner for personalized, timely, and reliable medical support services worldwide. https://x.com/AMIGlobalAssist Personal data, pas...

Victim:   |  Group: 
GB flag

brightwayconsultants.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2024-05-23 19:36

Brightway Consultants Ltd is a chartered surveying firm based in London. They offer comprehensive surveying services tailored to clients' individua...

Victim:   |  Group: 
CA flag

fortify.pro 

Company logo
Ransomware Group:

Discovery Date: 2024-05-08 09:24

Sector: Technology
The Canadian company has been developing high-quality and reliable software for corporate needs since 2015. They are renowned professionals of soft...

Victim:   |  Group: 
GB flag

www.servicepower.com 

Company logo
Ransomware Group:

Discovery Date: 2024-05-02 15:06

Sector: Technology
Large software development company Service Power. Great Britain. Documents of internal systems, credits to internal resources. 328 MB

Victim:   |  Group: 
CZ flag

www.credio.eu 

Company logo
Ransomware Group:

Discovery Date: 2024-05-02 15:05

Sector: Financial
Czech company Credio. IT consulting, electronic document management. Credits to internal systems. 11 MB

Victim:   |  Group: 
DE flag

melting-mind.de 

Company logo
Ransomware Group:

Discovery Date: 2024-04-29 06:08

Sector: Technology
German company melting-mind.de. IT systems company operating throughout Europe and offering a wide range of services in all areas of information te...

Victim:   |  Group: 
US flag

www.trifecta.com 

Company logo
Ransomware Group:

Discovery Date: 2024-04-22 21:57
Estimated Attack Date: 2024-04-05

Information: Trifecta is a trusted advisor for some of the most widely recognized and successful companies in the world. Brands choose Trifecta bas...

Victim:   |  Group: