Cyber Security News

0APT Ransomware Group Claims 200 Victims but Fails to Deliver Any Real Data

A new ransomware operation called 0APT surfaced on the dark web in late January 2026, claiming over 200 breached organizations within its first week.

The group established a professional data leak site on a vanity TOR domain and marketed itself as Ransomware-as-a-Service to recruit affiliates.

However, security researchers quickly determined that nearly all claimed victims were fabricated, with no genuine stolen data available. The operation appears designed to defraud aspiring cybercriminals rather than extort legitimate organizations.

The 0APT group built elaborate infrastructure including a data leak site powered by NGINX servers, a functional RaaS panel, and chat systems for negotiations.

Each victim listing displayed file trees supposedly containing gigabytes of corporate data. When researchers tried downloading files, they discovered impossibly large sizes exceeding 4GB for file trees that should measure only kilobytes.

Downloads automatically terminated after five minutes. THE RAVEN FILE analysts identified this as a deliberate deception tactic creating the illusion of successful breaches without delivering real information.

Multiple cybersecurity firms including GuidePoint Security, Halcyon, and SOCRadar investigated and found no evidence that listed organizations suffered actual breaches.

Operation center (Source – The Raven File)

Some claimed victims like Epworth HealthCare publicly stated they found no compromise.

Researchers discovered 0APT listed fictional entities such as “Metropolis City Municipal” inspired by DC Comics. The group’s claim rate far exceeded established ransomware operations, with reports showing 91 victims added in two days.

The RaaS Panel Deception Strategy

The operation’s true purpose emerged when researchers accessed the RaaS panel. The platform allowed affiliates to generate five ransomware samples per account, supporting Windows, Linux, and macOS.

Windows executables compiled using Rust measured 5.6MB, while Linux binaries were 1.3MB. These samples utilized encryption algorithms including AES256, Salsa20/ChaCha, and the rare Speck cipher associated with AI-generated code.

0APT RaaS Panel (Source – The Raven File)

Generated ransomware appends the .0apt extension and drops README0apt.txt containing unique victim identifiers.

Security Check (Source – The Raven File)

The operation recruited affiliates through prominent “JOIN RAAS” notifications, collecting fees from cybercriminals believing they joined a successful ecosystem.

One actor reportedly defrauded interested criminals of at least $85,000. The panel featured payment tracking, negotiation chat, admin support, and technical documentation.

While the malware functions when executed, the entire victim list was engineered to attract paying affiliates.

Security teams should confirm breach claims through official channels before responding to ransom demands.

Without genuine ransom notes, encrypted files, or direct communication, leak site listings should be considered potentially fabricated.

Organizations are advised to monitor for 0APT indicators of compromise, as functional ransomware binaries remain in circulation.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago