0APT Ransomware Group Claims 200 Victims but Fails to Deliver Any Real Data
In late January 2026, a ransomware operation named 0APT emerged on the dark web, asserting it had breached over 200 organizations within its first week. The group established a data leak site on a TOR domain and positioned itself as…
In late January 2026, a ransomware operation named 0APT emerged on the dark web, asserting it had breached over 200 organizations within its first week. The group established a data leak site on a TOR domain and positioned itself as Ransomware-as-a-Service (RaaS) to attract affiliates.
Security researchers found that most of the supposed victims were fictitious and that no genuine stolen data was present. The 0APT operation seems aimed at defrauding potential cybercriminals instead of extorting legitimate organizations.
The 0APT group developed extensive infrastructure, including a data leak site powered by NGINX servers, a RaaS panel, and negotiation chat systems. Each victim listing showed file trees claiming to contain corporate data. However, attempts to download these files revealed unrealistic sizes, exceeding 4GB for what should be kilobyte-sized file trees, and downloads terminated after five minutes. Analysts identified this as a deliberate tactic to create an illusion of successful breaches without delivering actual data.
Investigations by cybersecurity firms such as GuidePoint Security, Halcyon, and SOCRadar confirmed no evidence of real breaches among the listed organizations. Some claimed victims, like Epworth HealthCare, publicly stated they found no compromise.
In late January 2026, a ransomware operation named 0APT emerged on the dark web, asserting it had breached over 200 organizations within its first week.
Research into the RaaS panel revealed its role in recruiting cybercriminals. Affiliates could generate ransomware samples supporting Windows, Linux, and macOS. Windows executables compiled using Rust measured 5.6MB, while Linux binaries were 1.3MB. These samples employed encryption algorithms such as AES256, Salsa20/ChaCha, and the rare Speck cipher.
The generated ransomware appends the .0apt extension and includes a README0apt.txt file with unique victim identifiers. The operation recruited affiliates through prominent notifications and collected fees from individuals believing they were joining a successful ecosystem, reportedly defrauding criminals of at least $85,000.
Despite the functionality of the malware, the victim list was fabricated to attract paying affiliates. Security teams are advised to verify breach claims through official channels before responding to ransom demands, and to consider leak site listings as potentially fabricated without genuine ransom notes or encrypted files.
Organizations should monitor for 0APT indicators of compromise as functional ransomware binaries remain in circulation.
Based on reporting by Cyber Security News.
