0APT, also known as 0apt_team or 0apt Team, is a financially motivated cybercrime operation that emerged in late January 2026. It operates data-leak and negotiation infrastructure and markets ransomware-as-a-service to affiliates. Its initial claims of hundreds of organizational breaches were largely fabricated, including fictional victims and purported proof packages containing dummy data, publicly available material, or unusable archives. These listings do not establish a reliable victim population or geographic targeting profile. Despite its fabricated breach claims, 0APT has functional ransomware for Windows and Linux. Its associated 0APT Locker family includes Rust-based file-encryption malware. The operation's ransom demands threaten publication of allegedly stolen information and notification of regulators, clients, and business partners. Its affiliate infrastructure includes payload generation, payment tracking, negotiation chat, and administrative support. In April 2026, 0APT compromised the affiliate administration panel of rival ransomware operation Krybit and published operational information, including plaintext operator and affiliate credentials. It demanded payment and threatened to expose the identities and locations of Krybit personnel. Krybit retaliated by compromising and defacing 0APT's leak infrastructure and publishing its operational data. This exposure further demonstrated the discrepancy between 0APT's inflated victim claims and its actual activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only because its alleged leak-site claims were identified as fake and removed from reporting data.
Engaged in reciprocal compromise and leakage of operational data with KryBit.
A ransomware group described as both an attacker and a victim in reciprocal compromises with KryBit. Mentioned as a comparison illustrating destructive rivalries between cybercrime groups.
Rival ransomware-as-a-service group that breached Krybit’s affiliate panel, leaked internal data, and was later retaliated against by Krybit.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.