0APT Hacked - And Then Got Hacked Back
ID: e66c7c3c-0fcb-5264-9605-02b22a5b1477
STIX ID: report--e66c7c3c-0fcb-5264-9605-02b22a5b1477
Feed Name: Ransomware ISAC Blog
Date Published: 2026-04-14
Date Updated: 2026-07-29
Author: [email protected] (Corsin Camichel, Dani [Varys] Z, Ellis Stannard, Eric Taylor, Katya Kandratovich)
**0APT vs Krybit — mutual compromise and public data exposure:** On 13 April 2026 0APT breached the Krybit ransomware group's admin panel and threatened to expose operators, then Krybit counter-hacked and published 0APT's server files (including passwd/shadow, bash_history, Tor hs_ed25519_secret_key), revealing operator identifiers, victim lists, Bitcoin wallets, and technical IOCs; the archive shows an Android (AnLinux/Parrot) Tor-hosted leak site, evidence of RaaS development, BYOVD research traces, and over 150 alleged victims across multiple critical sectors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
