On July 24, 2026, the ransomware group known as APT73/Bashe publicly claimed responsibility for a cyberattack against Metrabyte Cloud Co., Ltd. (metrabyte.cloud), a prominent cloud service provider based in Thailand. The group posted an extortion notice on its leak infrastructure, threatening to publish stolen data unless the company opens negotiations. As of reporting, the claim is confirmed via the actor's own public posting, though the full scope of exfiltrated data has not yet been independently verified.
What Happened
APT73/Bashe added Metrabyte Cloud to its data-leak site with an extortion notice stating: "The full leak will be published soon, unless a company representative contacts us via the channels provided." This follows the group's established double-extortion playbook, in which victims are named publicly and given a window to pay before stolen data is released. The targeting of a cloud service provider is notable, as a successful compromise at this layer can cascade downstream to the provider's hosted customers.
What Was Taken
The specific volume, file types, and sensitivity of the stolen data have not been disclosed by the threat actor beyond the assertion that "sensitive data" is held and a "full leak" is pending. For a cloud service provider, the potential exposure is significant and may include customer account records, hosted databases, authentication credentials, configuration files, and internal operational data. Until a sample or full dump is posted, the exact contents remain unconfirmed, but the risk profile for both Metrabyte and its downstream clients should be treated as high.
Why It Matters
Attacks against cloud service providers carry outsized strategic risk because a single intrusion can expose the data of many tenant organizations simultaneously. APT73/Bashe's public naming of Metrabyte creates immediate reputational, regulatory, and supply chain pressure. Downstream customers relying on metrabyte.cloud infrastructure should assume potential exposure and begin their own assessments rather than waiting for confirmation. The incident also reinforces a broader trend of ransomware crews prioritizing high-leverage targets whose compromise multiplies extortion pressure across an entire customer base.
The Attack Technique
The initial access vector for this specific incident has not been publicly disclosed. Ransomware operators of this type commonly gain entry through stolen or reused credentials sourced from infostealer malware logs and dark web markets, phishing, exposed remote access services, and unpatched external-facing systems. Groups such as APT73/Bashe frequently establish persistence, escalate privileges, and exfiltrate data prior to issuing an extortion demand. Organizations should treat leaked credentials tied to their domains and personnel as a leading indicator, as these often surface weeks before a public ransom demand.
What Organizations Should Do
- Launch a compromise assessment: Initiate a full incident review to determine how attackers may have entered, what data could have been exfiltrated, and whether persistence mechanisms remain active.
- Validate and isolate backups: Ensure backups are current, encrypted, and stored offline, and adopt immutable backup solutions to resist ransomware encryption and deletion.
- Enforce MFA and credential hygiene: Require multi-factor authentication across all access points and reset credentials that may have been exposed via infostealer logs or dark web markets.
- Monitor dark web and leak sites: Track ransomware leak sites, stolen credential markets, and malware log dumps for exposure tied to your domains, email addresses, and key personnel.
- Integrate threat intelligence: Feed relevant indicators of compromise into your SIEM or XDR platform for real-time alerting and correlation.
- Engage professional responders: Involve incident response experts, threat analysts, and legal counsel before any dialogue with the threat actor.
Sources: APT73/Bashe Ransomware Attack on Metrabyte Cloud Co., Ltd. - DeXpose
TWEET: Metrabyte Cloud, a Thai cloud provider, breached by APT73/Bashe ransomware. Group posted an extortion notice threatening a full data leak unless negotiations begin. Full breakdown: https://wasteland.me/intel/metrabyte-cloud-apt73-bashe-ransomware #CyberSecurity #ThreatIntel