0APT, also known as 0apt Team, is a financially motivated cybercriminal ransomware and purported ransomware-as-a-service (RaaS) operation that emerged in January 2026. It operates a leak-site and affiliate-oriented infrastructure and has distributed functional ransomware payloads, including Rust-based lockers that encrypt files using AES and RSA cryptography. The operation advertised builders for Windows, Linux, and macOS payloads and used extortion messaging that threatened encryption, public data release, and reputational pressure against affected organizations. 0APT rapidly claimed hundreds of victims shortly after launching its leak site, but multiple investigations found no evidence that it had compromised most—or any—of the initially named organizations. Its purported proof packages included fabricated, corrupted, placeholder, scraped, or otherwise non-credible material, and at least one listed victim was fictional. The inflated victim claims appear to have been intended to establish credibility, attract RaaS affiliates, or induce fear-based payments. Despite the unreliability of its public victim claims, its ransomware samples and supporting RaaS infrastructure were assessed as operational. In April 2026, 0APT publicly extorted the rival Krybit ransomware operation after obtaining and releasing purported affiliate-panel data. It threatened to expose Krybit operators and affiliates and offered assistance to Krybit victims. Krybit subsequently retaliated by compromising 0APT infrastructure, disrupting its leak site, and releasing operational material that suggested 0APT maintained a web-based leak and RaaS environment. No reliable attribution to a specific country, established ransomware family, or state sponsor has been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only because its alleged leak-site claims were identified as fake and removed from reporting data.
Engaged in reciprocal compromise and leakage of operational data with KryBit.
Rival ransomware-as-a-service group that breached Krybit’s affiliate panel, leaked internal data, and was later retaliated against by Krybit.
Rival ransomware-as-a-service operator involved in a mutual breach and leak-site defacement conflict with Krybit.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.