Uptime Hamster: 10d 11h 12mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza 0apt

0apt

3 incidentes 1 paises 0 sectores ransomware IN Ultimo: 2026-06-29
Aliases: 0Apt Syndicate, TG-0110, APT3, Buckeye, UPS Team, Group 6, Boyusec – the Guangzhou Boyu Information Technology Company, Ltd, apt-c-12, apt12, bluemushroom, dnscalc, dyncalc, ixeshe, APT 18, APT 30, APT 38, APT 45
Ver en IntelTracker → APTTrail →
0apt, also known as the 0APT Syndicate, is a controversial Ransomware-as-a-Service (RaaS) operation that first emerged publicly on January 28, 2026, driven by financial motivation through extortion. The group quickly gained attention by listing numerous alleged victims on its dark web leak site, though many claims were found to be unsubstantiated or based on fabricated data. 0apt distinguishes itself by employing psychological warfare, relying on the sheer volume of alleged compromises and the fear of reputational damage rather than consistently delivering verifiable proof of data exfiltration or encryption. Despite operating functional ransomware infrastructure, technical analysis frequently reveals 0-byte dummy files or random data instead of genuine stolen information, indicating a significant bluffing component in their operations. While initially presenting as a politically neutral syndicate, source code analysis suggests a potential origin from South Asia, with internal comments

Aliases del actor

0Apt SyndicateTG-0110APT3BuckeyeUPS TeamGroup 6Boyusec – the Guangzhou Boyu Information Technology CompanyLtdapt-c-12apt12bluemushroomdnscalcdyncalcixesheAPT 18APT 30APT 38APT 45apt-c-60apt-q-12spyglacelaretpinarAPT CARDERBEEcrimson collectivem00nlightAPT DRIFTINGCLOUDdinodasdinodasratlinodaslinodasratevapiks

Actores similares

apt-onyxsleetactor · 1apt-sharppandaactor · 1Stone Pandaapt · 0Nightshade Pandaapt · 0Eloquent Pandaapt · 0apt-1877teamactor · 1apt-hackingteamactor · 1apt-twistedpandaactor · 1Mustang Pandaapt · 1APT27 (Emissary Panda)actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositoriounknowngithub.comRansom Notes: 0apt (1 notes from ThreatLabz)
DLS / onionunknownoaptxiyisljt2kv3we2we34kuudmqda7f2geffoylzpeo7ourhtz4dad.onion0apt
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: 0apt
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (SOCRadar)

United Arab EmiratesAustriaAustraliaBangladeshBelgiumBahrainCanadaSwitzerlandGermanyDenmark

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturing

URLs nuevas detectadas en IntelTracker

github.com ransomware.anggipradana.com

Victimas (1)

Ransom Notes: 0apt (1 notes from ThreatLabz)18 Jun 2026
Report
0apt - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de rescate …