0APT Ransomware Group Claims 200 Victims, Fails to Provide Proof
A new ransomware-as-a-service (RaaS) entity, identified as 0APT, has emerged, claiming to have compromised approximately 200 victims. However, the group has not provided verifiable proof of these claims.
A new ransomware-as-a-service (RaaS) entity, identified as 0APT, has emerged, claiming to have compromised approximately 200 victims. However, the group has not provided verifiable proof of these claims.
On or around January 28, 2026, 0APT launched a dark web data leak site, rapidly listing alleged victims. This aggressive approach has raised concerns among security researchers regarding the legitimacy of the group's activities.
Despite a professional infrastructure appearance, evidence suggests that 0APT's operations may be more focused on gaining notoriety and attracting affiliates rather than executing a legitimate ransomware campaign.
The group's Tor-based data leak site lists nearly 200 supposed victims, providing a victim-detail page for each, with large data archives purportedly over 4 GB in size. However, researchers have found that downloads from the site are unreliable, often stalling or stopping, thus preventing access to the claimed data.
Instead of actual exfiltrated files, the backend seems to stream incomplete or meaningless data, simulating large leak sizes without delivering usable content. This behavior, coupled with the absence of compromised database screenshots or internal documents, contrasts with established ransomware groups that typically publish proof-of-compromise samples.
Security teams investigating companies listed on 0APT's site have reported no evidence of intrusion, further questioning the group's claims.
A new ransomware-as-a-service (RaaS) entity, identified as 0APT, has emerged, claiming to have compromised approximately 200 victims.
0APT has developed a convincing facade, using a vanity .onion address for its data leak site and mimicking the branding and operational style of established ransomware syndicates.
The site is structured like a double-extortion portal with branded logos and victim pages. It also includes features like "COCHAT" for contact and "JOCHAT" for RaaS recruitment, along with a "RaaSDash" dashboard for affiliates.
Affiliates can generate Windows and Linux builds, manage negotiations, view payment status, and interact with "Admin Support," mirroring the workflow of mature RaaS programs. However, features such as "SUBMIT DETAILS" have appeared and disappeared across revisions, indicating an experimental backend possibly using off-the-shelf web widgets.
Test builds generate Windows executables of approximately 5–6 MB and smaller ELF binaries for Linux, employing AES-256 encryption and appending the ".0apt" extension. Configuration files allow selective targeting and encryption tuning, suggesting a moderately featured locker design.
Static analysis reveals cryptographic and encoding primitives, implying parts of the codebase may be sourced from existing templates. The presence of the Speck cipher, used in AI-generated ransomware, suggests potential use of generative AI tools during development.
Despite this, detections remain low, with few antivirus engines flagging samples, emphasizing the need for behavioral defenses.
Dubious Credibility and Risks to Defenders
0APT's campaign raises suspicion due to its high victim count claims, lack of verifiable data, auto-failing downloads, and absence of proof-of-compromise. This may indicate an attempt to deceive organizations and affiliates by promoting a RaaS platform not proven in real-world attacks.
For defenders, it is crucial to approach 0APT claims with caution, validating them against internal data and incident response procedures. Organizations listed on the 0APT site likely face a reputational bluff rather than confirmed compromise. However, security teams should perform due diligence to rule out unrelated intrusions and use available indicators to enhance detections.
Based on reporting by GBHackers.
