A new ransomware operation calling itself 0APT surfaced on dark web infrastructure in early 2026, promoting itself as a ransomware-as-a-service (RaaS) and claiming it had breached 200+ organizations in a very short period. Multiple investigations found the victim list and “leak” materials to be largely non-credible, including listings for apparently fictional entities and public denials from named organizations that they had been compromised. Researchers assessed the campaign as primarily designed to create the illusion of mass breaches to attract or defraud would-be affiliates rather than to extort confirmed victims.
Technical review of 0APT’s infrastructure described an onion-based leak site and a RaaS panel that allowed affiliates to generate limited numbers of ransomware builds and advertised multi-platform targeting (including Windows, Linux, and macOS), with Windows payloads described as Rust-based. The “downloadable” leak content showed suspicious behavior—claimed dataset sizes that did not align with the presented file trees and downloads that failed to complete in practical time—along with a lack of preview evidence (e.g., screenshots) typically used by established ransomware groups to prove exfiltration. While the public-facing campaign appeared to be a bluff, researchers cautioned that the presence of functioning RaaS tooling could still enable the operators to evolve into a more operational threat if they successfully recruit affiliates.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A Barricade Cyber Solutions threat intelligence report published on 2026-04-13 describes a panel breach involving the Krybit ransomware operation and attributes the activity to 0APT. This represents a specific operational incident tied to 0APT beyond its earlier suspected bluff campaign.
Despite the apparent bluff campaign, investigators reported that 0APT's generated ransomware binaries appeared to be functional. Defenders were advised to verify breach claims through official channels and monitor for 0APT indicators of compromise.
By mid-February 2026, multiple researchers and security firms concluded that 0APT's victim claims were mostly fake, citing fabricated file trees, broken downloads, denials from named organizations, and at least one fictional victim. The findings suggested the operation was likely aimed at scamming would-be affiliates rather than reflecting genuine large-scale extortion activity.
Shortly after appearing, 0APT publicly claimed it had compromised over 200 victims within its first week of operation. The group used leak-site listings and purported victim data to project rapid success and attract affiliates.
In late January 2026, a purported ransomware group called 0APT emerged on dark web forums, advertising itself as a ransomware-as-a-service platform. It promoted infrastructure including a TOR leak site, affiliate panel, negotiation chat, and cross-platform ransomware builders.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
id-ransomware.blogspot.com
Open sourcebarricadecyber.com
Open sourcecybersecuritynews.com
Open sourcecyderes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.