Threat intelligence researchers reported that a newly surfaced actor calling itself 0APT/0apt launched a dark web “leak site” and rapidly posted a large set of purported victims—mixing real brand names with clearly fabricated entities—which triggered incident-response activity at some named organizations. S-RM assessed the operation as an impostor ransomware effort, noting examples of obviously fictional victims (including names suggestive of LLM-generated or pop-culture-derived entities) and warning that the scale and sector spread of the claimed victim list is atypical even for major historical campaigns.
Independent analysis cited by DataBreaches.net similarly concluded the “leaks” are not stolen data: downloads linked from the site reportedly produce endless streams of random bytes rather than exfiltrated files, consistent with piping a randomness source such as /dev/random to visitors. Both write-ups assess the activity as a scam or deception operation—potentially to pressure listed companies into paying, waste defenders’ time, or lure other criminals—advising organizations named on the site to validate claims with due diligence and respond proportionately rather than initiating large-scale technical remediation solely based on the postings.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that 0apt's posted 'leaks' do not contain stolen data. Instead, the download links appear to stream effectively endless randomly generated data, likely /dev/random output, suggesting the operation is intended to waste analysts' time and trigger panic rather than publish exfiltrated files.
A new dark web leak-site group calling itself 0apt began posting numerous victim listings, including major recognizable companies, creating the appearance of a broad ransomware or extortion campaign. The references do not provide a specific launch date, so this is inferred from the first reporting on the activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.