0APT
Incident posture
Timeline
Summary
0APT had its administrators, affiliates and operational data exposed after a rival ransomware group leaked logs, source code and system files from its infrastructure, defaced its leak site and left a warning message. This followed its earlier posting of a fabricated victim list and claims of attacks on other ransomware operators.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
0APT emerged in late January 2026 with a data leak blog that posted a list of nearly 200 alleged victims over the course of a week. Researchers noted that the list lacked corroborating evidence and was widely regarded as fabricated. Despite the skepticism, analysts assessed that 0APT possessed functioning ransomware encryptors. The group failed to attract affiliates or gain traction and subsequently went quiet for several months. In mid‑April 2026, 0APT reemerged by deleting its earlier victim list and claiming to have conducted ransomware attacks against other ransomware operators. The claimed targets included KryBit, Everest (which had been active since 2020), and RansomHouse (active since 2021).
KryBit had appeared in late March 2026, offering ransomware‑as‑a‑service kits for Windows, Linux, ESXi and network‑attached storage devices under an 80/20 affiliate model. During its first two weeks, KryBit published details of ten legitimate victims on its leak site. Following 0APT’s claims, KryBit’s infrastructure and personnel were exposed, revealing two administrators, five affiliates, approximately twenty potential victims and ransom demands ranging from $40,000 to $100,000. In retaliation, KryBit breached 0APT’s systems, exfiltrated operational data such as access logs, PHP source code and system files, listed 0APT as a victim on its own leak site and left the message “Next time, don't play with the big boys.” After the exchange, 0APT has been unable to restore its leak site or resume operations, while KryBit continues to maintain the defacement of the 0APT leak page. The incident provided defenders with rare insight into the internal tools and communications of both ransomware groups.
Sources
Sources available to members: 1 source.