CSIDB logo
Incident

KryBit

Incident posture

Attack window
Apr 2026
Location
-
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 23:59

Linked entities

Victim
KryBit
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Apr 2026
Discovered
Undetermined
Disclosed
Apr 2026
Resolved
Pending

Summary

Two ransomware‑as‑a‑service groups, 0APT and KryBit, turned on each other after 0APT resurfaced with claims of having attacked KryBit and other ransomware operators. 0APT’s earlier victim list was found to be fabricated, but KryBit possessed genuine victims and exposed two administrators, five affiliates, about twenty potential targets and ransom demands ranging from $40,000 to $100,000. In retaliation, KryBit breached 0APT’s infrastructure, exfiltrated access logs, PHP source code and system files, listed 0APT as a victim on its leak site and left a taunting message. The leak left 0APT unable to recover while KryBit maintained control of the defaced leak site.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

0APT emerged in late January with a list of nearly 200 victims posted to its data leak blog over the course of a week. This list was widely regarded as fabricated because of a lack of evidence pointing toward victim compromises. Halcyon assessed 0APT did use functioning encryptors. The actor failed to pick up traction or affiliates, and went quiet for months. KryBit emerged in late March, offering RaaS kits targeting Windows, Linux, ESXi, and network-attached storage (NAS) devices, using an 80/20 affiliate model. The group published 10 legitimate victims in its first two weeks.

Then in mid-April, 0APT reemerged, deleting its previous list of fake victims while claiming ransomware attacks against ransomware operators including KryBit, Everest (active since 2020), and RansomHouse (active since 2021). KryBit had both its infrastructure and personnel exposed, revealing two administrators, five affiliates, 20 potential victims, and ransom demands between $40,000 and $100,000. In response, KryBit breached and exfiltrated 0APT's infrastructure, listed the latter as a victim, and left a message on 0APT's leak site: "Next time, don't play with the big boys." The researchers said 0APT's initial victim list was entirely fabricated, with no data exfiltrated. KryBit leaked 0APT's operational data set, including access logs, PHP source code, and system files.

0APT has been unable to recover, and KryBit maintains defacement of the 0APT leak site.

Sources

Sources available to members: 1 source.

CSIDB