TL;DR
APT73, also operating under the alias Bashe, launched as a LockBit copycat in April 2024 with a reputation for theatrical fraud — fabricating breaches to recruit affiliates. By April 2026 the theatrics stopped mattering: the group is now actively compromising real targets at volume, posting 8+ new victims in a single 24-hour window including Sharjah Electricity, Water, and Gas Authority (SEWA) — a UAE government-owned critical utility. Alongside Egyptian petroleum infrastructure, two Saudi Arabian organizations, and a major Mexican distributor, APT73's April 2026 campaign marks a decisive geographic and sector pivot toward MENA energy and utilities. For organizations in the Gulf region, this crew is no longer background noise.
Background: Born From LockBit's Shadow
In April 2024, a new ransomware actor appeared on the dark web and immediately did something unusual: it named itself an Advanced Persistent Threat. The "APT" designation carries weight in threat intelligence circles — it typically signals state-sponsored, long-horizon operations like Lazarus, APT29, or APT41. For a financially motivated ransomware crew to self-label as APT73 was widely read as either hubris or a recruitment gambit. Both readings were correct.
APT73's data leak site (DLS) launched with a layout nearly identical to LockBit's — the same countdown timers, the same victim-shaming format, the same offer to "extend" deadlines for payment. This wasn't coincidence. LockBit's builder leaked publicly in September 2022 after a disgruntled developer published it. That single event has since spawned dozens of derivative operations; APT73/Bashe is among the more persistent inheritors of that codebase.
Early analysis from CloudSEK (January 2025) flagged the group as practicing "cyber theater" — claiming responsibility for breaches it didn't execute, recycling old leak data to manufacture credibility, and masking Personally Identifiable Information (PII) in posted samples to prevent independent verification of authenticity. The goal was simple: attract affiliates who would trust the brand enough to hand over real compromises in exchange for a cut of ransom proceeds.
By mid-2025, that model appeared to be working. BlackFog's State of Ransomware 2026 report confirmed Bashe was posting legitimate victim data — the fabrication phase had given way to genuine operational capacity. The affiliate network had grown.
Technical Profile: What APT73 Actually Looks Like
Encryptor and Builder
APT73's encryptor is derived from the LockBit 3.0 leaked builder (also known as LockBit Black). The builder, which leaked verbatim onto GitHub in 2022, provides:
- AES-256 encryption for file contents
- RSA-2048 asymmetric wrapping for key exchange with the C2
- Configurable extensions — APT73 samples have been observed appending
.basheor pseudorandom extensions similar to LockBit behavior - Shadow copy deletion via
vssadmin delete shadows /all /quietexecuted pre-encryption - Safe mode reboot persistence — same trick LockBit used to evade endpoint detection by rebooting into Safe Mode before encrypting
The ransom note drops a file named !!!READ_ME!!!.txt with a TOR-based contact URL routed through the group's .onion site.
Initial Access: IAB-Dependent Model
Like most modern ransomware operations, APT73 does not do its own initial access at scale. The group operates a Ransomware-as-a-Service (RaaS) model where Initial Access Brokers (IABs) provide pre-compromised network footprints — typically via:
- Exposed RDP and VPN endpoints (Fortinet, Citrix, SonicWall flaws are perennial favorites)
- Phishing-delivered infostealer logs purchased on dark web markets (Raccoon, Vidar, RedLine outputs)
- Exploited public-facing applications — the Q1 2026 explosion of RMM and perimeter device CVEs provides ready material
Once inside, observed post-exploitation TTPs follow a recognizable pattern:
| Phase | Technique | MITRE ID |
|-------|-----------|----------|
| Discovery | ADRecon, BloodHound for AD enumeration | T1087, T1069 |
| Lateral Movement | Pass-the-Hash, SMB relay | T1550.002 |
| Persistence | Scheduled tasks, registry run keys | T1053, T1547 |
| Exfiltration | Rclone to attacker-controlled cloud storage | T1537 |
| Impact | LockBit-derived encryptor, shadow copy deletion | T1486, T1490 |
The critical observation: data exfiltration occurs before encryption. APT73 follows the modern double-extortion playbook — steal first, encrypt second. This means the ransom clock starts ticking long before victims realize they're being ransomed.
Targeting Logic
APT73 applies relatively deliberate victim selection:
- Revenue threshold: $10M–$500M annual revenue. This band maximizes payment probability — organizations large enough to afford meaningful ransoms but not so large as to have fortress-grade defenses or unlimited legal resources.
- Sectors: Financial services, banking, IT services, manufacturing — historically. The April 2026 campaign expands this to energy utilities and petroleum infrastructure.
- Geography: Launched in North America and Europe, expanded to Asia-Pacific by mid-2024, and is now executing a clear MENA campaign — the region's digital transformation boom has expanded the attack surface faster than defenses have matured.
The April 2026 MENA Campaign: Analysis
The past 48 hours have produced the most geographically concentrated APT73 campaign on record. All confirmed or high-confidence victims:
1. Sharjah Electricity, Water, and Gas Authority (SEWA) — UAE 🇦🇪
Posted: 2026-04-27 | Site: shj.ae
SEWA is a government-owned critical utility serving the Sharjah emirate — one of the UAE's seven emirates. As the sole provider of electricity, water, and gas services to Sharjah's 1.7 million residents and its extensive industrial zones, SEWA represents exactly the category of critical national infrastructure that Western agencies have been warning about for years.
APT73's leak post describes the victim as a "critical public utility" and claims exfiltration of operational data. No ransom amount is publicly stated; the post uses countdown-timer pressure tactics. If SEWA's operational technology (OT) network has any connectivity to the IT side — a common architectural weakness in utilities modernizing infrastructure — the risk profile extends beyond data exfiltration.
Why this matters: Sharjah's utility systems serve major industrial clients including Hamriyah Free Zone and Sharjah Airport. A successful data exfiltration from SEWA could expose supplier contracts, operational schedules, and potentially network topology that informs future OT-targeting campaigns.
2. Alexandria Petroleum Company — Egypt 🇪🇬
Egypt's petroleum sector is a primary target for both state-sponsored espionage and financially motivated extortion. Alexandria Petroleum Company operates within Egypt's strategic hydrocarbon network. The APT73 claim cites sensitive operational data exfiltration.
3. Al-Gosaibi Group (GTB) — Saudi Arabia 🇸🇦
Al-Gosaibi is a major Saudi conglomerate with interests in financial services, shipping, and industrial operations. The targeting aligns with APT73's financial services preference but the scale of the entity (multi-billion-dollar group) represents an upward tier creep.
4. Al Rawdah Cooperative Society — Saudi Arabia 🇸🇦
A Saudi cooperative organization in the agricultural/food distribution sector. Cooperatives often have lower IT maturity than commercial enterprises, making them attractive for ransomware operators prioritizing ease-of-access over target prestige.
5. Grupo Principal — Mexico 🇲🇽
Posted: 2026-04-27
A leading Mexican distribution company. The Latin American inclusion alongside the MENA cluster suggests either different affiliate-sourced compromises converging on the same publication date, or a deliberate broadening of geographic footprint.
6. banak.com — Financial Services
A banking-sector victim consistent with APT73's longstanding financial services focus.
Aggregate assessment: Six confirmed victims in ~48 hours, with #1 being UAE critical national infrastructure. This is not the same group that was fabricating breach claims in early 2024. APT73 has either acquired experienced affiliates with genuine operational capacity or is operating under new management with significantly elevated tradecraft.
The "Fake APT" Problem: Why the Label Stuck and Why It Now Matters Less
APT73's choice to brand itself as an Advanced Persistent Threat — a designation it transparently does not merit by any intelligence community definition — initially made it easy to dismiss. Real APTs are tracked by nation states, funded by governments, and operate with mission-level objectives beyond financial gain.
But APT73's brand choice has had an unintended second-order effect: it attracted affiliates who wanted to associate with an "APT-level" operation. The dark web ransomware marketplace rewards reputation. By positioning itself as more sophisticated than it was, APT73 created the conditions for a self-fulfilling prophecy — affiliates with real skills joining a crew that marketed itself as elite.
CloudSEK's 2025 warning about fabricated claims was accurate at the time. The group's evolution since then follows a pattern observed in other RaaS operations: fake-it-till-you-make-it affiliate recruitment works. LockBit itself built its early reputation partly through aggressive marketing on cybercrime forums before delivering the tooling to back up the claims.
By Q1 2026, APT73's claimed victims include:
- Malindo Air (Southeast Asian airline)
- Betclic (European online gambling)
- Federal Bank India
- Line Bank
- Bank Rakyat Indonesia
- And now a UAE government utility and Egyptian petroleum infrastructure
The fabrication phase appears to be over. The operational phase is underway.
IOCs / Indicators of Compromise
Note: These are derived from public reporting and dark web monitoring. Direct attribution to specific file hashes requires sandboxed sample analysis.
Network Indicators (known APT73/LockBit-derived infrastructure):
- TOR-based DLS:
bashe[.]pro(dark web, not directly accessible) - Rclone C2 exfiltration to legitimate cloud providers (Mega, Dropbox, AWS S3 buckets with randomized names)
- Cobalt Strike Beacon C2 traffic patterns (LockBit-affiliated operators' most common post-exploitation framework)
Host-Based Indicators:
vssadmin delete shadows /all /quiet— pre-encryption shadow copy deletionbcdedit /set {default} safeboot minimal— Safe Mode persistence trick- Registry keys consistent with LockBit 3.0:
HKLM\SOFTWARE\LockBit(some variants) - File extension:
.basheor pseudorandom 9-character extension appended - Ransom note filename:
!!!READ_ME!!!.txtorBASHE_README.txt - Process:
conhost.exespawning unusual child processes (common evasion)
MITRE ATT&CK Mapping:
- T1486 — Data Encrypted for Impact
- T1537 — Transfer Data to Cloud Account
- T1078 — Valid Accounts (IAB-purchased credentials)
- T1190 — Exploit Public-Facing Application
- T1053.005 — Scheduled Task (persistence)
- T1490 — Inhibit System Recovery (VSS deletion)
- T1069 — Permission Groups Discovery (AD enumeration)
- T1550.002 — Pass the Hash
Lyrie Take
APT73/Bashe represents a category of threat that autonomous defense platforms must specifically model: the "credibility-bootstrapped RaaS" that evolves its actual capability alongside its marketing.
The traditional approach to threat intelligence would have flagged APT73 as "unverified/low-confidence" based on CloudSEK's 2025 fabrication analysis and moved on. That assessment was correct in 2025. The problem: threat actor profiles have a half-life that most enterprises aren't operationally equipped to manage. APT73 that was "probably fake" in January 2025 is unambiguously real in April 2026 — and it just hit UAE critical infrastructure.
The key detection window is exfiltration, not encryption. By the time a ransomware encryptor fires, the data is gone, the clock is running, and the choice is pay or suffer public exposure. APT73's model — like all modern double-extortion RaaS — means the breach is complete before the ransom demand arrives. Detection must happen at the data movement phase: Rclone running on endpoints, large outbound transfers to cloud storage providers during off-hours, Cobalt Strike beacon callouts, AD enumeration via BloodHound.
The MENA campaign pivot is geopolitically timed. The region is experiencing simultaneous:
1. Digital transformation acceleration (UAE smart city initiatives, Saudi Vision 2030)
2. Geopolitical volatility (Middle East conflict context, energy sector attention)
3. Under-resourced OT/IT convergence security in legacy utilities
Attackers follow the combination of high value + emerging digital surface + under-defended. SEWA is a textbook example of all three. Organizations across the Gulf should treat APT73's SEWA claim as a sector-wide signal, not an isolated incident.
Defender Playbook
Immediate (0-72 hours) — MENA Energy/Utility Operators:
1. Credential hygiene audit: Pull all service accounts with RDP/VPN access. Force rotation on any account older than 90 days or with failed login attempts in the past 30 days. IAB-sold access is almost always credential-based.
2. Rclone detection: Search endpoints and servers for rclone.exe or rclone binary (often renamed — look for the binary signature, not just the name). APT73 operators use Rclone for bulk exfiltration to cloud storage. Create an alert: any process making outbound connections to mega.nz, dropbox.com, or storage.googleapis.com in volumes >1GB/hour from server-class machines.
3. VSS protection: Enable Windows Defender's Protected Folders feature. Deploy a canary VSS shadow copy and alert on its deletion. Add vssadmin to your process creation monitoring exclusion list as a high-confidence ransomware pre-indicator.
4. Safe Mode lockdown: Block the bcdedit /set safeboot command via AppLocker or Windows Defender Application Control policies. LockBit-derived ransomware's Safe Mode reboot trick is well-documented and detectable.
5. AD enumeration visibility: Enable logging for LDAP queries, group enumeration, and BloodHound-characteristic request patterns (bulk group membership queries). Canary admin accounts in AD that should never be queried — alert on any lookup.
Medium-term (1-4 weeks) — All Organizations:
6. IAB exposure check: Use your threat intelligence platform to check whether your domain, VPN credentials, or email addresses appear in infostealer logs circulating on dark web markets. Vidar, Raccoon, and RedLine logs are actively traded; your credentials may already be staged for sale.
7. Perimeter hardening: APT73 affiliates favor unpatched Fortinet (CVE-2024-21762 still relevant), Cisco ASA, and exposed RDP. Inventory all internet-facing services and validate patch status against the CISA KEV catalog.
8. Segmentation audit: If you operate OT/ICS environments with any IT connectivity — utilities, industrial operators — validate that air-gap or segmentation policies are enforced and not just documented. APT73's SEWA claim warrants OT-specific review for any MENA utility.
9. Tabletop exercise: Run a double-extortion scenario: attacker has exfiltrated 50GB. The ransom note has arrived. What is your decision tree? Who decides whether to pay? What is the regulatory disclosure timeline in your jurisdiction? For UAE entities: NESA's cyber incident reporting requirements apply.
10. Threat actor tracking: Add APT73/Bashe to your active monitoring queue. Subscribe to RedPacket Security, DarkFeed, or equivalent dark web monitoring for new victim posts. The group is posting daily — knowing whether you're on their list requires active dark web presence monitoring, not periodic manual checks.
Sources
1. CloudSEK — "Unmasking Media-Hungry Ransomware Groups: Bashe (APT73)" (January 2025): https://www.cloudsek.com/blog/unmasking-media-hungry-ransomware-groups-bashe-apt73
2. BlackFog — "The State of Ransomware 2026": https://www.blackfog.com/the-state-of-ransomware-2026/
3. RedPacket Security — "[APT73] Ransomware Victim: shj[.]ae" (April 2026): https://www.redpacketsecurity.com/apt73-ransomware-victim-shj-ae/
4. DeXpose.io — "APT73/Bashe Attacks Alexandria Petroleum Company" (April 2026): https://www.dexpose.io/apt73-bashe-attacks-alexandria-petroleum-company/
5. DeXpose.io — "APT73/Bashe Targets Mexican Distribution Leader Grupo Principal" (April 2026): https://www.dexpose.io/apt73-bashe-targets-mexican-distribution-leader-grupo-principal/
6. DeXpose.io — "APT73/Bashe Targets Saudi Arabia's Al Rawdah Cooperative Society" (April 2026): https://www.dexpose.io/apt73-bashe-targets-saudi-arabias-al-rawdah-cooperative-society/
7. PurpleOps Ransomware Activity Tracker 2026: https://purple-ops.io/blog/ransomware-tracker-2026
8. Zensec — "APT73 Ransomware" profile (July 2025): https://zensec.co.uk/apt73-ransomware/
9. SOCRadar — "Dark Web Profile: Bashe (APT73)" (January 2025): https://socradar.io/blog/dark-web-profile-bashe-apt73/
10. MITRE ATT&CK — LockBit group profile and associated TTPs: https://attack.mitre.org/
Lyrie.ai Cyber Research Division — Senior Analyst Desk
Lyrie Verdict
Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.