KryBit
Incident posture
Timeline
Summary
Two ransomware‑as‑a‑service groups, 0APT and KryBit, turned on each other after 0APT resurfaced with claims of having attacked KryBit and other ransomware operators. 0APT’s earlier victim list was found to be fabricated, but KryBit possessed genuine victims and exposed two administrators, five affiliates, about twenty potential targets and ransom demands ranging from $40,000 to $100,000. In retaliation, KryBit breached 0APT’s infrastructure, exfiltrated access logs, PHP source code and system files, listed 0APT as a victim on its leak site and left a taunting message. The leak left 0APT unable to recover while KryBit maintained control of the defaced leak site.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
0APT emerged in late January with a list of nearly 200 victims posted to its data leak blog over the course of a week. This list was widely regarded as fabricated because of a lack of evidence pointing toward victim compromises. Halcyon assessed 0APT did use functioning encryptors. The actor failed to pick up traction or affiliates, and went quiet for months. KryBit emerged in late March, offering RaaS kits targeting Windows, Linux, ESXi, and network-attached storage (NAS) devices, using an 80/20 affiliate model. The group published 10 legitimate victims in its first two weeks.
Then in mid-April, 0APT reemerged, deleting its previous list of fake victims while claiming ransomware attacks against ransomware operators including KryBit, Everest (active since 2020), and RansomHouse (active since 2021). KryBit had both its infrastructure and personnel exposed, revealing two administrators, five affiliates, 20 potential victims, and ransom demands between $40,000 and $100,000. In response, KryBit breached and exfiltrated 0APT's infrastructure, listed the latter as a victim, and left a message on 0APT's leak site: "Next time, don't play with the big boys." The researchers said 0APT's initial victim list was entirely fabricated, with no data exfiltrated. KryBit leaked 0APT's operational data set, including access logs, PHP source code, and system files.
0APT has been unable to recover, and KryBit maintains defacement of the 0APT leak site.
Sources
Sources available to members: 1 source.