0APT
Profile
Organisation tracking is available to eligible accounts.
Profile narrative
0APT is a threat actor group that operates within the cybercriminal ecosystem, primarily associated with ransomware operations and the public disclosure (or "leaking") of stolen data from victim organisations. The group maintains an online leak site — a dark web portal typically used by ransomware affiliates to pressure victims into paying extortion demands — and uses this infrastructure both to publish allegedly stolen data and to publicise its claimed intrusions. In addition to its core extortion activity, 0APT has been involved in feuds with other ransomware operators, including the posting of claims about attacks on rival groups, which situates it within the broader intra-criminal conflicts that occasionally surface among ransomware actors.
In April 2026, a rival ransomware group breached 0APT's own infrastructure, exfiltrating operational material and exposing the group's administrators, affiliates and internal data. The rival leaked logs, source code and system files, defaced 0APT's leak site and left a warning message. This incident occurred shortly after 0APT had posted a fabricated victim list and had made claims about attacks on other ransomware operators, suggesting that the prior publicity may have provoked retaliatory action from peers in the underground ecosystem. The exposure of administrator and affiliate identities is significant because such leak sites are normally controlled exclusively by the operating group, and the defacement demonstrated that 0APT's operational security had been compromised by a competing threat actor.
No publicly available information about the geographic origin, size, leadership structure, formal corporate ownership or formal affiliations of 0APT is present in the source material. The group is known only by its alias and is not described as a subsidiary of, or as being owned by, any other entity; it appears to function as an independent criminal collective rather than as a registered organisation. Likewise, there is no confirmed information regarding specific sectors or geographic markets that 0APT targets, the volume of victims it has claimed, or any quantitative metrics about its revenue, reach or operational footprint.
What distinguishes 0APT from many peer ransomware groups is its involvement in public disputes with other ransomware operators and its willingness to make unverified claims about attacks on rivals, including the publication of a false victim roster. This pattern indicates a group that, in addition to conventional extortion activity, engages in information operations directed at competitors within the cybercriminal underground. The April 2026 breach and defacement of its own leak site underscore the volatility of that competitive environment and the operational risks that even established leak-site operators face from rival actors. Beyond these confirmed facts, any further characterisation of 0APT's capabilities, specialisation, or market positioning would require additional sourcing beyond the material available.
Incidents
1 incident linked to this organisation.