Feuding Ransomware Groups Leak Each Other's Data
ID: 62582884-c24c-5151-b265-eb3f77c595d2
STIX ID: report--62582884-c24c-5151-b265-eb3f77c595d2
Feed Name: Dark Reading
This report summarizes Halcyon Ransomware Research Center findings on a feud between RaaS actors 0APT and KryBit: 0APT initially published a large, largely fabricated victim list, then KryBit exposed 0APT by leaking its access logs, source code, and system files, proving many 0APT claims false. KryBit and Everest are identified as legitimate ransomware threats with published victims and ransom demands; the disclosures include IOCs and defensive guidance (monitor for data staging/exfiltration, validate backups, deploy anti-ransomware defenses). The intelligence value of exposed tooling and TTPs is highlighted as useful for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
