CSIDB logo
Incident

0APT

Incident posture

Attack window
Apr 2026
Location
-
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-16 02:53

Linked entities

Victim
0APT
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Jan 2026
Resolved
Pending

Summary

0APT had its administrators, affiliates and operational data exposed after a rival ransomware group leaked logs, source code and system files from its infrastructure, defaced its leak site and left a warning message. This followed its earlier posting of a fabricated victim list and claims of attacks on other ransomware operators.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

0APT emerged in late January 2026 with a data leak blog that posted a list of nearly 200 alleged victims over the course of a week. Researchers noted that the list lacked corroborating evidence and was widely regarded as fabricated. Despite the skepticism, analysts assessed that 0APT possessed functioning ransomware encryptors. The group failed to attract affiliates or gain traction and subsequently went quiet for several months. In mid‑April 2026, 0APT reemerged by deleting its earlier victim list and claiming to have conducted ransomware attacks against other ransomware operators. The claimed targets included KryBit, Everest (which had been active since 2020), and RansomHouse (active since 2021).

KryBit had appeared in late March 2026, offering ransomware‑as‑a‑service kits for Windows, Linux, ESXi and network‑attached storage devices under an 80/20 affiliate model. During its first two weeks, KryBit published details of ten legitimate victims on its leak site. Following 0APT’s claims, KryBit’s infrastructure and personnel were exposed, revealing two administrators, five affiliates, approximately twenty potential victims and ransom demands ranging from $40,000 to $100,000. In retaliation, KryBit breached 0APT’s systems, exfiltrated operational data such as access logs, PHP source code and system files, listed 0APT as a victim on its own leak site and left the message “Next time, don't play with the big boys.” After the exchange, 0APT has been unable to restore its leak site or resume operations, while KryBit continues to maintain the defacement of the 0APT leak page. The incident provided defenders with rare insight into the internal tools and communications of both ransomware groups.

Sources

Sources available to members: 1 source.

CSIDB