Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: APT28, Jumpy Pisces, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, COLDRIVER, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Blue Callisto, Cobalt Group, GOLD KINGSWOOD, COBALT SPIDER, G0080, Mule Libra, JerseyMikes, TURBINE PANDA, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon, T-APT-04, GOLD DRAKE, Turbine Panda, Hippo Team, Magecart Group 4, India, other aliases, several other aliases, is a sophisticated, Turla, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, Fancy Bear, tracked as, RansomedSupport, the ALPHV Ransomware Group, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig, Chrysene, Velvet Chollima, HIDDEN COBRA, ZINC, Labyrinth Chollima, Guardians of Peace, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Sofacy, ALPHV Blackcat, Sparkling Pisces, Mailto, Circus Spider, APT33, Royal, BlackSuit, UNC3944, Starfraud, Muddled Libra, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, VOLTZITE, for follow-on operations, Paper Werewolf, Rare Werewolf, Rezet, Head Mare, Unicorn, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, LAUNDRY BEAR, FoxBlade, Lotus Blossom, Lotus Panda, Bronze Elgin, Parisite, Pioneer Kitten, UNC757, FruityArmor, UNK_RemoteRogue, 0Apt Syndicate, has publicly claimed, KeyBoys, SaffronRose, Saffron Rose, AjaxSecurityTeam, Group 26, Sayad

Description

0APT surfaced on the dark web in late January 2026 as an ostensible Ransomware‑as‑a‑Service (RaaS) platform that marketed free access to a Rust‑based encryptor and claimed a rapid hit rate of over 200 victims. Official ransomware samples have not been verified, yet traffic analyses show typical RaaS infrastructure: a command‑and‑control framework, a web portal for download, and a leak site on Tor offering allegedly stolen data. From the technical evidence available, the malware exhibits classic double‑extortion behavior: it first exfiltrates files via outbound C2 channels (likely over encrypted HTTP/TCP) then encrypts victim data with a custom Rust binary that adds a proprietary extension and deletes shadow copies to hinder recovery. The actor also leverages supply‑chain tactics—compromising third‑party service providers or web applications—and relies on post‑exploitation tools such as Brute Ratel, Cobalt Strike, PowerShell, WMI, and PsExec for lateral movement. While analysts note credible technical depth in the Rust code and infrastructure design, the sheer velocity of alleged “victim” claims coupled with a lack of independently verifiable decryptors strongly suggests many reports are inflated incidents or sandbox self‑attribution attacks. Consequently, 0APT should be treated with caution, particularly by smaller organizations that may inadvertently engage with its RaaS portal.

TTP Summary

Supply-chain attacks such as strategic web compromise (SWC) where the actor compromise 3rd-party service provider hosting the victim websites

Goals & Targeting

Objectives

Ransomware
Financial Gain

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Healthcare
Critical infrastructure
Manufacturing
Education
Energy
Media
Non profit
Transportation
Aerospace
Aviation
Retail
Hospitality
Utilities
Pharmaceutical
Construction
Think tank
Mining
Gaming
Legal services
Information technology
Maritime
Chemical
Nuclear
Oil gas
Entertainment
Aerospace & defense
Legal

Targeted Countries / Regions

US
RU
CN
TW
IR
VN
KR
IN
UA
IL
JP
AE
PK
GB
AU
SA
TR
BR
KP
CA
SG
DE
BY
MX
ES
PL
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

Grounded in web research
· analyzed in 16 chunks · 3 days ago

Executive Summary

0APT presents itself as a high‑velocity ransomware‑as‑a‑service (RaaS) operation claiming hundreds of victims, but most evidence indicates the majority of those claims are fabricated through sandbox backscatter or fake data. The group appears to employ a Rust‑based encryptor that appends a ".0apt" extension and uses a double‑extortion model involving data exfiltration before encryption. In short, 0APT is likely a hoax aimed at defrauding other cybercriminals rather than posing a real threat to legitimate organizations.

Goals & Targeting

The primary objective of 0APT is financial gain through ransomware payouts, amplified by the double‑extortion model to pressure victims into paying. While it targets a broad spectrum—government, finance, infrastructure, healthcare, and other public‑service sectors—the lack of verified attacks implies that its strategic intent may be more opportunistic, exploiting the reputational damage caused by fake claims and using the RaaS façade to siphon funds from less sophisticated criminals or early adopters.

Enhanced Description

Key Capabilities

  • Ransomware-as-a-Service offering
  • Rust-based encryptor adding a .0apt extension
  • Double‑extortion model (data exfiltration + encryption)
  • Supply‑chain compromise and web shell deployment
  • Use of post‑exploitation frameworks (Cobalt Strike, Brute Ratel)
  • Credential harvesting via phishing and brute force
  • Lateral movement with PowerShell, WMI, PsExec, RDP
  • Shadow copy deletion
  • Web-based downloader/loader families (Latrodectus, Lotus Loader)

MITRE ATT&CK Tactics

Initial Access
Execution
Privilege Escalation
Persistence
Discovery
Collection
Credential Access
Lateral Movement
Command and Control
Exfiltration
Impact
Defense Evasion

ATT&CK Techniques

T1064
T1543
T1053
T1055
T1021.001
T1016
T1049
T1005
T1486
T1048
T1566.001
T1003
T1192
T1193
T1086
T1078
T1105
T1059
T1041
T1566
T1195
T1189
T1110
T1068
T1059.001
T1021.004
T1112
T1060
T1050
T1071.001
T1190
T1203
T1497
T1136.001
T1059.007
T1047
T1489

Software / Tooling

0APT ransomware (Rust‑based)
Brute Ratel
Cobalt Strike
Latrodectus downloader
Lotus Loader
PowerShell
WMI
PsExec
RDP
Shadow copy tool

Campaigns & Victims

Although 0APT has declared activity across more than 30 nations and a wide range of sectors, evidence suggests its campaign patterns are inconsistent. Sporadic reports of successful attacks—such as the alleged breach of Cobalt Mining Corp—are outweighed by numerous fabricated victim claims generated via sandbox backscatter or fake data releases. Operational tempo is rapid but largely unsubstantiated; real attacks appear sporadic and likely limited to opportunistic, low‑profile targets rather than large, coordinated assaults typical of state‑aligned campaigns.

IOC Patterns

  • File hash (md5)
  • Domain (example: TEMP.Zagros, Ransomware.live)
  • URL
  • Web shell file paths
  • Rust binary signatures
  • .0apt file extension
  • Shadow copy deletion indicator
  • Exfiltration traffic patterns
  • PowerShell script execution
  • Registry modification entries for persistence
  • RDP or WMI connection attempts

Recommended Actions

  • Verify any stated compromise via forensic analysis before responding; avoid paying to unverified RaaS claims.
  • Block known 0APT domains, IPs, and onion addresses using perimeter firewalls and threat feeds.
  • Maintain up‑to‑date backups with immutable storage and test ransomware recovery procedures.
  • Enforce MFA on all privileged accounts and lockdown RDP/SSH access. Implement endpoint detection & response (EDR) that flags Rust binaries, payload downloaders (Latrodectus/Lotus Loader), web shells, and abnormal PowerShell activity. Patch and harden internet‑facing services to mitigate supply‑chain and exploitation attack vectors. Deploy data loss prevention (DLP) to detect exfiltration attempts prior to encryption. Educate users about spearphishing, social engineering links, ZIP‑archive traps, and the risks of downloading software from unknown RaaS portals.

ATT&CK Techniques

Defense impairment
1 technique
Privilege Escalation
1 technique

Software / Tooling

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 20

References

  1. www.huntress.com — Cited by web research for: Turla
  2. ics-cert.kaspersky.com — Cited by web research for: Fancy Bear
  3. cloud.google.com — Cited by web research for: STOP
  4. attack.mitre.org — Cited by web research for: Payload
  5. businessinsights.bitdefender.com — Cited by web research for: Clop
  6. www.paloaltonetworks.com — Cited by web research for: Unknown
  7. www.halcyon.ai — Cited by web research for: 0Apt Syndicate

Intel Summary

43

Techniques

66

Tools

7

Campaigns

44

IOCs

0

Observed Data

14

Tactics

Tags

Ransomware
APT
Critical Infrastructure
Criminal
Financial gain
Medium sophistication
ransomware
criminal
financial-gain
medium-sophistication
extortion
global-targeting

Details

MITRE ID
APT26
Type
Criminal
Sophistication
Medium
Resource Level
Government
Primary Motivation
Organizational gain
Country of Origin
Russia (RU)
Confidence
80%
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.