Also known as: APT28, Jumpy Pisces, first identified in 2014, 0mid16B, Cobalt Gang, Slayer Kitten, GOLD HERON, Phantom Panda, Alloy Taurus, Granite Typhoon, Callisto, SEABORGIUM, TA446, Evil Corp, the Latrodectus downloader, the Lotus loader family, Transparent Tribe, APT36, Gold Southfield, SideWinder, APT-C-17, Rattlesnake, APT39, Chafer, Sodinokibi, first observed in 2019, APT37, Selective Pisces, governments, MuddyWater, Seedworm, TEMP.Zagros, Mercury, APT26, Volt Typhoon, Bronze Silhouette, DEV-0391, Snake, Venomous Bear, Group 88, Waterbug, Turla Team, Krypton, Uroburos, SIG23, MAKERSMARK, IRON HUNTER, COLDRIVER, GOSSAMER BEAR, BlueCharlie, Star Blizzard, TAG-53, IRON FRONTIER, UNC4057, Blue Callisto, Cobalt Group, GOLD KINGSWOOD, COBALT SPIDER, G0080, Mule Libra, JerseyMikes, TURBINE PANDA, BRONZE EXPRESS, TECHNETIUM, Taffeta Typhoon, T-APT-04, GOLD DRAKE, Turbine Panda, Hippo Team, Magecart Group 4, India, other aliases, several other aliases, is a sophisticated, Turla, Uroboros, DEV-0832, Vanilla Tempest, is a notorious ransomware, APT15, Ke3chang, Fancy Bear, tracked as, RansomedSupport, the ALPHV Ransomware Group, Comment Crew, MenuPass, Red Apollo, Stone Panda, Gothic Panda, UPS Team, Pirate Panda, Buckeye, Reaper, ScarCruft, APT35, Phosphorus, Ajax Security Team, ITG18, Cozy Bear, Carbon Spider, GOLD NIAGARA, Sangria Tempest, ITG14, TA505, Hive0065, APT34, OilRig, Chrysene, Velvet Chollima, HIDDEN COBRA, ZINC, Labyrinth Chollima, Guardians of Peace, ALPHV, Gleaming Pisces, BokBot, PlayCrypt, Sofacy, ALPHV Blackcat, Sparkling Pisces, Mailto, Circus Spider, APT33, Royal, BlackSuit, UNC3944, Starfraud, Muddled Libra, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, VOLTZITE, for follow-on operations, Paper Werewolf, Rare Werewolf, Rezet, Head Mare, Unicorn, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, LAUNDRY BEAR, FoxBlade, Lotus Blossom, Lotus Panda, Bronze Elgin, Parisite, Pioneer Kitten, UNC757, FruityArmor, UNK_RemoteRogue, 0Apt Syndicate, has publicly claimed, KeyBoys, SaffronRose, Saffron Rose, AjaxSecurityTeam, Group 26, Sayad
0APT surfaced on the dark web in late January 2026 as an ostensible Ransomware‑as‑a‑Service (RaaS) platform that marketed free access to a Rust‑based encryptor and claimed a rapid hit rate of over 200 victims. Official ransomware samples have not been verified, yet traffic analyses show typical RaaS infrastructure: a command‑and‑control framework, a web portal for download, and a leak site on Tor offering allegedly stolen data. From the technical evidence available, the malware exhibits classic double‑extortion behavior: it first exfiltrates files via outbound C2 channels (likely over encrypted HTTP/TCP) then encrypts victim data with a custom Rust binary that adds a proprietary extension and deletes shadow copies to hinder recovery. The actor also leverages supply‑chain tactics—compromising third‑party service providers or web applications—and relies on post‑exploitation tools such as Brute Ratel, Cobalt Strike, PowerShell, WMI, and PsExec for lateral movement. While analysts note credible technical depth in the Rust code and infrastructure design, the sheer velocity of alleged “victim” claims coupled with a lack of independently verifiable decryptors strongly suggests many reports are inflated incidents or sandbox self‑attribution attacks. Consequently, 0APT should be treated with caution, particularly by smaller organizations that may inadvertently engage with its RaaS portal.
Supply-chain attacks such as strategic web compromise (SWC) where the actor compromise 3rd-party service provider hosting the victim websites
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
0APT presents itself as a high‑velocity ransomware‑as‑a‑service (RaaS) operation claiming hundreds of victims, but most evidence indicates the majority of those claims are fabricated through sandbox backscatter or fake data. The group appears to employ a Rust‑based encryptor that appends a ".0apt" extension and uses a double‑extortion model involving data exfiltration before encryption. In short, 0APT is likely a hoax aimed at defrauding other cybercriminals rather than posing a real threat to legitimate organizations.
Goals & Targeting
The primary objective of 0APT is financial gain through ransomware payouts, amplified by the double‑extortion model to pressure victims into paying. While it targets a broad spectrum—government, finance, infrastructure, healthcare, and other public‑service sectors—the lack of verified attacks implies that its strategic intent may be more opportunistic, exploiting the reputational damage caused by fake claims and using the RaaS façade to siphon funds from less sophisticated criminals or early adopters.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Although 0APT has declared activity across more than 30 nations and a wide range of sectors, evidence suggests its campaign patterns are inconsistent. Sporadic reports of successful attacks—such as the alleged breach of Cobalt Mining Corp—are outweighed by numerous fabricated victim claims generated via sandbox backscatter or fake data releases. Operational tempo is rapid but largely unsubstantiated; real attacks appear sporadic and likely limited to opportunistic, low‑profile targets rather than large, coordinated assaults typical of state‑aligned campaigns.
IOC Patterns
Recommended Actions
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
No observed data linked yet.
43
Techniques
66
Tools
7
Campaigns
44
IOCs
0
Observed Data
14
Tactics