Ransomware groups 0APT and KryBit turned on each other in a public dark-web feud, with 0APT threatening to dox people tied to KryBit unless it was paid and publishing a sample of allegedly stolen KryBit files. Researchers cited in the reporting said the sample included plaintext credentials linked to KryBit operators and affiliates, plus five cryptocurrency wallet addresses, while 0APT also tried to lure KryBit victims by offering help recovering encrypted data. The clash expanded beyond threats when KryBit reportedly hacked 0APT, defaced its leak site, and exposed internal data from the rival operation.
Analysis from Halcyon said the mutual leaks damaged both gangs, forcing infrastructure rebuilds and likely rebranding, while also undermining their credibility. Leaked 0APT access logs suggested its claims of more than 190 victims since launching in January were fabricated and that no victim data had been exfiltrated, while leaked KryBit negotiation data showed about 20 potential victims and ransom demands ranging from $40,000 to $100,000. The dispute also touched Everest Group, whose encoded and hashed publication and user data was reportedly exposed, highlighting mounting pressure inside the ransomware ecosystem as falling crypto ransom revenues intensify competition among criminal groups.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Halcyon assessed that the mutual leaks harmed both 0APT and KryBit, forcing infrastructure rebuilds and likely rebranding. The report also noted Everest Group data had been leaked, though Everest had not retaliated at that time.
Data exposed during the feud showed KryBit administrator, affiliate, and victim negotiation records spanning late March to mid-April 2026. The leak referenced 20 potential victims and ransom demands ranging from $40,000 to $100,000.
Researchers reviewing the leaked sample said it contained plaintext credentials tied to KryBit operators and affiliates, along with five cryptocurrency wallet addresses. They also found no evidence that KryBit had received ransom payments.
0APT posted on its leak infrastructure that it would expose identities, photos, names, locations, and other details of people affiliated with KryBit unless paid. It also published a sample of allegedly stolen KryBit files and offered to help KryBit victims recover data.
KryBit struck back by compromising 0APT, defacing its leak site, and exposing 0APT internal data. Leaked access logs indicated 0APT's claimed 190-plus victims since January were fabricated and that no victim data had actually been exfiltrated.
At the start of the feud, 0APT publicly claimed it had compromised rival ransomware groups KryBit, RansomHouse, and Everest Group. This triggered a broader criminal-on-criminal conflict later documented by Halcyon.
0APT began operating in January 2026. Later reporting and Halcyon analysis described it as a legitimate ransomware threat with credible technical depth, though some early victim claims were likely exaggerated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcego.theregister.com
Open sourcetheregister.com
Open sourcetheravenfile.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.