Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareRansomwareUsed by 1 actor

0APT

0APT is a purported ransomware operation that surfaced on dark web forums in late January 2026, marketing itself as a Ransomware-as-a-Service (RaaS) with a professional-looking ecosystem (vanity TOR data leak site, RaaS panel, and negotiation chat). Multiple investigations (including GuidePoint Security, Halcyon, SOCRadar, THE RAVEN FILE, and Intel 471) assessed that 0APT’s claimed victim list and “stolen data” were largely fabricated—e.g., implausible multi-terabyte “file trees,” downloads that terminated after ~5 minutes, and samples that contained repeating null bytes—suggesting the operation was primarily designed to scam would-be affiliates (reportedly defrauding at least $85,000) rather than extort real organizations. Some named victims publicly denied compromise (e.g., Epworth HealthCare), and at least one listed entity was fictional (e.g., “Metropolis City Municipal”).

Despite the apparent fraud around breach claims, researchers who accessed the RaaS panel reported it could generate functional ransomware samples (up to five builds per affiliate account) for Windows, Linux, and macOS. Generated samples were described as Rust-compiled on Windows (~5.6MB) and ~1.3MB on Linux, using encryption algorithms including AES-256 and Salsa20/ChaCha, and referencing the Speck cipher. The ransomware appends the .0apt extension to encrypted files and drops a ransom note named README0apt.txt containing unique victim identifiers. Intel 471 reported an alleged 0APT malware sample but assessed it appeared to be a work in progress rather than fully operational ransomware, while noting a small possibility the actor was testing infrastructure/capabilities for future activity.

Known/mentioned indicators and behaviors from reporting include: file extension “.0apt”; ransom note “README0apt.txt”; and (as recommended hunt focus areas associated with claimed 0APT activity) suspicious PowerShell execution-policy changes to Unrestricted, PowerShell-based file download methods, WMI remote command attempts, nonstandard SMB communication/profiling, SMB share/admin share activity, WinRAR archive creation, and shadow copy deletion via OS utilities.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
0APT

"Intel 471 discovered the alleged 0APT malware sample... technical analysis of the malicious file indicated it was more of a work in progress than a fully operational ransomware malware sample."

via intel471intel471.com
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

0APT | Mallory