INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Ransomware Groups Leak Each Other's Data in Feud

| 2026-04-28 20:13 CRITICAL LOW RANSOMWARE & EXTORTION DATA BREACH
Executive Summary
AI-generated
On April 28, 2026, a feud between two ransomware-as-a-service (RaaS) actors, 0APT and KryBit, led to the exposure of both groups' data. The Halcyon Ransomware Research Center reported that 0APT emerged in late January with nearly 200 victims listed on its blog, although this list was later deemed fabricated due to a lack of evidence pointing towards victim compromises. In response, 0APT reemerged and claimed ransomware attacks against KryBit, Everest, and RansomHouse. Meanwhile, KryBit had both its infrastructure and personnel exposed after breaching and exfiltrating 0APT's data set, listing the latter as a victim, and leaving a message on 0APT's leak site. This incident affected approximately five affiliates of KryBit and potentially up to 20 victims. The attack works by exposing rival groups' admin panels, affiliate data, and victim negotiations in an attempt to gain credibility without actual ransom payments or compromised victims. As of the reported date, both 0APT and KryBit appear to be inactive following their respective breaches.
Technical Mitigations AI-generated
• Data Backup (ATT&CK mitigation for Defacement): Consider implementing IT disaster recovery plans that contain procedures for taking regular data backups that can be used to restore organizational data. Ensure backups a • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Tropic TrooperTropic Trooper WiperWiper
Target & Sectors
DPRK DPRK
Incident Timeline
‎January 2026
Threat actors from feuding ransomware groups, including Tropic Trooper and KryBit, leaked each other's data.
threat_actor Tropic Trooper
‎2026/04/28
0APT reemerged in mid-April, deleting its previous list of fake victims and claiming ransomware attacks against KryBit, Everest, and RansomHouse.
infrastructure Macos
infrastructure Windows
financial 2.0 Ransomware Acts
victims 200 victims
infrastructure Linux
victims 190 victims
victims 10 legitimate victims
victims 20 potential victims
Tactical Metrics
Metrics
infrastructure
‎Macos
Affected Product
Metrics
victims
200
Victims
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
financial
2
Ransomware Acts
Metrics
victims
190
Victims
Metrics
victims
10
Legitimate Victims
Metrics
victims
20
Potential Victims
Intelligence Sources
Dark Reading 2026-04-28