NEWS 150 hacks, and the archives are empty. What's wrong with the "formidable" hackers from 0APT

MOON ADM

Well-known member
Member
Joined
Jan 22, 2026
Messages
101
Reaction score
999
We tell you why companies should not panic yet.

1771104097743.png

At the beginning of 2026, a new player appeared in cyberspace — the 0APT group, which announced the creation of its own "extortion as a service" platform. In a few weeks, she managed to make a fuss, provoking a real panic in the information security services of a number of companies. Meanwhile, Intel 471 specialists have determined that most of the group's statements are most likely lies.

0APT appeared in January 2026 and promptly published a list of more than 150 allegedly hacked organizations on its Tor leaks website. It was the speed and scale of the statements that alerted analysts. The files that the group presented as evidence of data theft reached several terabytes each, but when partially downloaded, they turned out to be filled with repeated zero bytes — that is, they did not contain any useful data. The "victims" themselves, for the most part, could not be verified and looked like artificially generated ones.

The situation escalated when the names of real companies began to appear among the listed targets. Some of them have already managed to launch internal incident response procedures. Nevertheless, Intel 471 concluded that there is no convincing evidence of real attacks: the detected sample of the group's malicious software turned out to be an unfinished development rather than a full-fledged encryption tool.

For comparison, in January 2026, the Qilin group committed the largest number of confirmed attacks — over 100 cases. In 2023, the CLOP group exploited vulnerabilities in managed file transfer servers and attacked about 130 victims. Unlike 0APT, both groupings have a proven history of real-world operations.

Despite the fact that the current activity of 0APT is regarded as unreliable, Intel 471 does not exclude that the group is testing the infrastructure for future attacks. In this regard, the team has developed a set of tools for searching for threats focused on the behavior typical of 0APT: suspicious PowerShell activity, creation of WinRAR archives, remote WMI commands, non-standard SMB interaction and deletion of shadow copies.

Experts recommend not initiating a large—scale response based on the mere appearance of an organization's name on a leak site - first you need to verify the authenticity of the evidence provided. If the data looks generated or corrupted, the claims should be treated with skepticism. Timely informing internal stakeholders about the nature of such fake threats helps to avoid panic and conserve the resources of the security team.
 
6,262Threads
84,984Messages
6,031Members
TeenelLatest member
Top Bottom