0APT Hacked - And Then Got Hacked Back
ID: 935bedc8-886c-593e-93ed-198829b759a8
STIX ID: report--935bedc8-886c-593e-93ed-198829b759a8
Feed Name: Ransomware ISAC Blog
Date Published: 2026-04-14
Date Updated: 2026-08-21
Author: [email protected] (Ransom-ISAC Research Team)
On 13–16 April 2026, the rival criminal groups 0APT and Krybit engaged in a public escalation: 0APT published a doxxing/extortion post targeting Krybit, and Krybit counter-hacked 0APT, exfiltrating Tor hidden-service keys, system credential files, bash history, server logs, and administrative panel data. The breach exposed operator identities, victim listings (150+ organisations), Bitcoin wallets, and actionable IOCs (onion address, host/platform, services, filenames), and revealed operator tooling and potential BYOVD research; the report includes artifact summaries, log analysis, and a 164 MB archive of recovered files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
