Researchers assessed a purported ransomware operation calling itself 0APT and found indicators it may be a scam rather than an active extortion group. The actor launched a data-leak site in late January and rapidly posted 200+ claimed victims within about a week—an unusually high tempo that often suggests a rebrand or splinter group, prompting closer scrutiny by GuidePoint Security.
Reporting indicates the 0APT narrative quickly unraveled after online observers flagged that many listed victims appeared fake (potentially AI-generated names). The group then took its leak site offline, later relaunching it with a smaller list of real organizations, but researchers said none of the alleged compromises have been substantiated; in at least two cases, organizations that conducted incident response investigations reportedly found no evidence of a breach. The operation also reportedly required a bitcoin “joining fee” for affiliates, reinforcing concerns that the brand is being used to monetize would-be partners rather than to conduct verified ransomware intrusions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
By 2026-04-30, reporting citing Halcyon said KryBit had compromised rival group 0APT and published extensive internal data in response to 0APT's earlier exposure of KryBit materials. The leaked data reportedly included 0APT access logs, system files, and PHP source code, while also revealing operational weaknesses in 0APT's leak-site infrastructure.
By 2026-04-15, 0APT had reportedly leaked selected data it claimed was stolen from the Krybit ransomware gang and threatened to expose Krybit affiliates unless the group negotiated or paid. Analysis of the leaked files reportedly found plaintext credentials for Krybit operators and affiliates and five cryptocurrency wallet addresses, while Krybit's website was experiencing outages.
On February 10-11, 2026, reporting citing GuidePoint Security, Kela, Bitdefender, and others concluded that 0APT was likely a scam or large-scale hoax aimed at defrauding cybercriminals and building false credibility. Some researchers cautioned that, despite the fake claims, the actors could still evolve into a real ransomware threat.
At least two organizations named by 0APT conducted incident response assessments and found no evidence of intrusion or data theft. These findings further undermined the group's extortion and leak claims.
0APT later brought its leak site back online with a much smaller set of named organizations after previously listing more than 200 victims. Researchers said the remaining organizations still had not been validated as genuinely breached.
After reports that many listed victims appeared fake, potentially including AI-generated entries, 0APT took its leak site offline. The outage followed scrutiny over the implausible scale and quality of its claimed victim disclosures.
By early February 2026, multiple security firms reported that 0APT's alleged victim data, leak-site file trees, and proof-of-compromise materials did not credibly support its claims. Analysts also noted no observed ransom notes, no decryptor demonstrations, and other inconsistencies that pointed to a hoax or inflated operation.
As the group emerged in late January 2026, 0APT advertised a ransomware-as-a-service affiliate program, including a 1 bitcoin joining or assessment fee. Researchers said its explicit request for applicants to demonstrate zero-day exploits suggested a predatory effort to steal valuable tools from would-be partners.
In late January 2026, a previously unknown group calling itself 0APT launched a data-leak site and rapidly began listing large numbers of purported victims. Early claims ranged from more than 90 to roughly 200 organizations within days.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.