INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Ransomware Groups Leak Each Other's Data in Feud
| 2026-04-28 20:13 CRITICAL LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
On April 28, 2026, a feud between two ransomware-as-a-service (RaaS) actors, 0APT and KryBit, led to the exposure of both groups' data. The Halcyon Ransomware Research Center reported that 0APT emerged in late January with nearly 200 victims listed on its blog, although this list was later deemed fabricated due to a lack of evidence pointing towards victim compromises. In response, 0APT reemerged and claimed ransomware attacks against KryBit, Everest, and RansomHouse. Meanwhile, KryBit had both its infrastructure and personnel exposed after breaching and exfiltrating 0APT's data set, listing the latter as a victim, and leaving a message on 0APT's leak site. This incident affected approximately five affiliates of KryBit and potentially up to 20 victims. The attack works by exposing rival groups' admin panels, affiliate data, and victim negotiations in an attempt to gain credibility without actual ransom payments or compromised victims. As of the reported date, both 0APT and KryBit appear to be inactive following their respective breaches.
Technical Mitigations AI-generated
• Data Backup (ATT&CK mitigation for Defacement): Consider implementing IT disaster recovery plans that contain procedures for taking regular data backups that can be used to restore organizational data. Ensure backups a
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Tropic TrooperTropic Trooper
WiperWiper
Target & Sectors
DPRK
DPRK
Incident Timeline
January 2026
Threat actors from feuding ransomware groups, including Tropic Trooper and KryBit, leaked each other's data.
Click on any entity below to view its context and source!
threat_actor
Tropic Trooper
Related:
Tropic Trooper APT Takes Aim at Home Routers, Japanese Targets
Totaro says gang feuds are a net positive for defenders.
2026/04/28
0APT reemerged in mid-April, deleting its previous list of fake victims and claiming ransomware attacks against KryBit, Everest, and RansomHouse.
Click on any entity below to view its context and source!
infrastructure
Macos
Related:
North Korea's Lazarus Targets macOS Users via ClickFix
That is not the case with KryBit, which had both its infrastructure and personnel exposed.
infrastructure
Windows
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
KryBit emerged in late March, offering RaaS kits targeting Windows, Linux,
ESXi
, and network-attached storage (NAS) devices, using an 80/20 affiliate model (where the RaaS affiliate keeps…
financial
2.0 Ransomware Acts
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
KryBit emerged in late March, offering RaaS kits targeting Windows, Linux,
ESXi
, and network-attached storage (NAS) devices, using an 80/20 affiliate model (where the RaaS affiliate keeps…
victims
200 victims
0APT emerged in late January with a list of nearly 200 victims posted to its data leak blog over the course of a week.
infrastructure
Linux
…ct 2.0 Ransomware Acts as Wiper, Thanks to Design Error
KryBit emerged in late March, offering RaaS kits targeting Windows, Linux,
ESXi
, and network-attached storage (NAS) devices, using an 80/20 affiliate model (where the RaaS affiliate keeps 80…
victims
190 victims
The access logs revealed that the 190+ victims initially posted by 0APT in January 2026 were entirely fabricated and no data was ever exfiltrated from any of the listed victims," the researchers said.
victims
10 legitimate victims
The group published 10 legitimate victims in its first two weeks.
victims
20 potential victims
This revealed that KryBit had two administrators, five affiliates, 20 potential victims, and ransom demands between $40,000 and $100,000.
Tactical Metrics
Metrics
infrastructure
Macos
Affected Product
Click for context!
Related:
North Korea's Lazarus Targets macOS Users via ClickFix
That is not the case with KryBit, which had both its infrastructure and personnel exposed.
Metrics
victims
200
Victims
0APT emerged in late January with a list of nearly 200 victims posted to its data leak blog over the course of a week.
Metrics
infrastructure
Windows
Affected Product
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
KryBit emerged in late March, offering RaaS kits targeting Windows, Linux,
ESXi
, and network-attached storage (NAS) devices, using an 80/20 affiliate model (where the RaaS affiliate keeps…
Metrics
infrastructure
Linux
Affected Product
…ct 2.0 Ransomware Acts as Wiper, Thanks to Design Error
KryBit emerged in late March, offering RaaS kits targeting Windows, Linux,
ESXi
, and network-attached storage (NAS) devices, using an 80/20 affiliate model (where the RaaS affiliate keeps 80…
Metrics
financial
2
Ransomware Acts
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
KryBit emerged in late March, offering RaaS kits targeting Windows, Linux,
ESXi
, and network-attached storage (NAS) devices, using an 80/20 affiliate model (where the RaaS affiliate keeps…
Metrics
victims
190
Victims
The access logs revealed that the 190+ victims initially posted by 0APT in January 2026 were entirely fabricated and no data was ever exfiltrated from any of the listed victims," the researchers said.
Metrics
victims
10
Legitimate Victims
The group published 10 legitimate victims in its first two weeks.
Metrics
victims
20
Potential Victims
This revealed that KryBit had two administrators, five affiliates, 20 potential victims, and ransom demands between $40,000 and $100,000.
Intelligence Sources
Dark Reading
2026-04-28
Feuding Ransomware Groups Leak Each Other's Data
Dark Reading
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T06:27
Comprehensive Tactical Telemetry
Highly Correlated Entities
11x
organisation
Identified Entity
Lazarus Targets macOS Users
entity
5x
tactic
Cyber Operation Type
Ransomware
tactic
4x
timeline
Temporal Reference
2020
date
3x
infrastructure
Affected Product
Macos
software
2x
target region
Target Country
Korea, Democratic People's Republic of
country
2x
victims
Victims
200
victims
2x
general metric
%
80
%
2x
attribution
Attributing Entity
Ransomware Actions Have Ransomware Consequences
Erika Totaro
authority
Contextual Telemetry
Context Block
6 METRICS
target region
Target Region
DPRK
region
malware
Malware Payload
Wiper
tool
financial
Ransomware Acts
2
ransomware acts
threat actor
APT Group
Tropic Trooper
actor
victims
Legitimate Victims
10
legitimate victims
victims
Potential Victims
20
potential victims
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.