0APT is a ransomware-branded cybercrime operation that emerged in late January 2026 and presented itself as a ransomware-as-a-service (RaaS) program under aliases including 0apt and 0apt_team. The group rapidly claimed more than 200 victims within days of launch, but multiple independent investigations found those claims were largely fabricated or unsubstantiated. Reported anomalies included fictional victim names, implausible proof artifacts, corrupted or meaningless sample data, absence of corroborating ransom notes or victim communications in many cases, and indications that the operation may have been designed in part to defraud prospective affiliates or extort organizations through fear rather than through demonstrated network compromise. Some reporting also assessed that 0APT solicited affiliates and may have sought to obtain valuable exploit capability from would-be partners. Despite the credibility problems around its victim claims, 0APT maintained operational ransomware infrastructure, including a leak site, negotiation mechanisms, and an affiliate panel. Researchers reported that its ransomware samples for Windows and Linux were functional, and separate malware reporting described a Rust-based encryptor commonly referred to as 0APT Locker that appends a distinctive extension to encrypted files and uses a ransom note threatening data leakage, regulator notification, and outreach to clients or partners. Public reporting also indicates the panel supported cross-platform payload generation, including Windows, Linux, and macOS variants, reinforcing that the group possessed at least some real malware-development capability even if its public victim narrative was deceptive. 0APT engaged in criminal-on-criminal activity as well as victim-facing extortion. In April 2026 it breached rival RaaS operation Krybit’s affiliate panel, leaked internal data, and threatened to expose Krybit affiliates unless paid. Krybit subsequently retaliated by compromising 0APT infrastructure, defacing its leak site, and publishing 0APT operational data. Reporting based on the exposed material stated that 0APT had fabricated many of its earlier victim claims. This conflict made 0APT notable within the 2026 ransomware ecosystem as an example of ransomware-on-ransomware disruption. Available reporting consistently characterizes 0APT’s dominant motive as financial. Its observed behavior includes extortion, data-leak threats, affiliate recruitment, and likely fraud directed at both organizations and other cybercriminals. Publicly claimed targeting was broad and opportunistic, with emphasis in reporting on health care, professional services, technology, transportation and logistics, energy, manufacturing, and other data-rich or critical-infrastructure-adjacent sectors. Most claimed victims were reported to be in the United States, but many of those claims remain unverified. No high-confidence attribution to a nation-state or a specific country of origin is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Rival ransomware-as-a-service group that breached Krybit’s affiliate panel, leaked internal data, and was later retaliated against by Krybit.
Rival ransomware-as-a-service operator involved in a mutual breach and leak-site defacement conflict with Krybit.
Named activity cluster/group whose ransomware-related activity peaked in February and then dropped to zero in March.
A nascent ransomware-as-a-service gang whose infrastructure was compromised by KryBit; it allegedly fabricated victim claims and operated a leak site based on AnLinux-ParrotOS using an Android device's internal SD card.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.