logo

0APT RANSOMWARE: The Real FAKE!

ID: f366ba3c-3bc9-550a-a712-38bbfe53bb7e

STIX ID: report--f366ba3c-3bc9-550a-a712-38bbfe53bb7e

Feed Name: THE RAVEN FILE

Threat Score
50/100

Date Published: 2026-02-14

Date Updated: 2026-04-19

Author: RakeshKrish

...
...

This analysis reviews the 0APT operation and its TOR-hosted data leak site and RAAS panel, concluding the public victim claims are likely fraudulent while confirming that the actor's panel can generate Windows and Linux ransomware builds (.0apt extension) which exhibit AES256 and other cryptographic primitives, include README0apt ransom notes, have low AV detection rates, and map to multiple MITRE ATT&CK techniques; the report highlights operational features, build-generation limits, sample hashes, and the risk that affiliates could turn the project into genuine ransomware infections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.