Uptime Hamster: 22d 12h 55mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza 0apt

0apt

3 incidentes 1 paises 0 sectores threat-actor IN Ultimo: 2026-06-29
Aliases: 0Apt Syndicate, Gothic Panda, TG-0110, lo que sugiere una operativa bien organizada, PLUTONIUM o Onyx Sleet en fuentes no verificadas, APT3, Buckeye, UPS Team, Group 6, Boyusec – the Guangzhou Boyu Information Technology Company, Ltd, apt-c-12, apt12, bluemushroom, dnscalc, dyncalc, ixeshe, APT 18
Ver en IntelTracker → APTTrail →
0apt, also known as the 0APT Syndicate, is a controversial Ransomware-as-a-Service (RaaS) operation that first emerged publicly on January 28, 2026, driven by financial motivation through extortion. The group quickly gained attention by listing numerous alleged victims on its dark web leak site, though many claims were found to be unsubstantiated or based on fabricated data. 0apt distinguishes itself by employing psychological warfare, relying on the sheer volume of alleged compromises and the fear of reputational damage rather than consistently delivering verifiable proof of data exfiltration or encryption. Despite operating functional ransomware infrastructure, technical analysis frequently reveals 0-byte dummy files or random data instead of genuine stolen information, indicating a significant bluffing component in their operations. While initially presenting as a politically neutral syndicate, source code analysis suggests a potential origin from South Asia, with internal comments

Aliases del actor

0Apt SyndicateGothic PandaTG-0110lo que sugiere una operativa bien organizadaPLUTONIUM o Onyx Sleet en fuentes no verificadasAPT3BuckeyeUPS TeamGroup 6Boyusec – the Guangzhou Boyu Information Technology CompanyLtdapt-c-12apt12bluemushroomdnscalcdyncalcixesheAPT 18APT 30APT 38APT 45apt-c-60apt-q-12spyglacelaretpinarAPT CARDERBEEcrimson collectivem00nlightAPT DRIFTINGCLOUDdinodasdinodasrat

Actores similares

apt-onyxsleetactor · 1apt-sharppandaactor · 1Stone Pandaapt · 0Nightshade Pandaapt · 0Eloquent Pandaapt · 0apt-1877teamactor · 1apt-hackingteamactor · 1apt-twistedpandaactor · 1APT27 (Emissary Panda)actor · 1VICEROY TIGERapt · 0

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: 0apt
Repositoriounknowngithub.comRansom Notes: 0apt (1 notes from ThreatLabz)
DLS / onionunknownoaptxiyisljt2kv3we2we34kuudmqda7f2geffoylzpeo7ourhtz4dad.onionmarktsec
Victimas
1
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (OSINT)

United Arab EmiratesAustriaAustraliaBangladeshBelgiumBahrainCanadaSwitzerlandGermanyDenmark

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingOther Information ServicesSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodationAir TransportationManufacturing

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com github.com

Victimas (1)

Ransom Notes: 0apt (1 notes from ThreatLabz)18 Jun 2026
Report
0apt - Ransom NotesEste grupo de ransomware tiene 1 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de rescate …