惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Proofpoint News Feed
云风的 BLOG
云风的 BLOG
Apple Machine Learning Research
Apple Machine Learning Research
Hugging Face - Blog
Hugging Face - Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Google DeepMind News
Google DeepMind News
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
B
Blog
月光博客
月光博客
博客园 - 【当耐特】
WordPress大学
WordPress大学
Microsoft Azure Blog
Microsoft Azure Blog
I
InfoQ
The GitHub Blog
The GitHub Blog
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
博客园 - Franky
MyScale Blog
MyScale Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Last Week in AI
Last Week in AI
B
Blog RSS Feed
H
Help Net Security

The Register - Security

Are we human? MyPillow must decide whether to be firm or soft as ransomware crims demand pay Experts pour cold borscht on Farage's Russian hack claim AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Techie claims Trump Mobile website was leaking thousands of people's data Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Microsoft open-sources agentic AI safety tools Are we human? America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shai-Hulud copycat worm infects yet another npm package MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data To gain root access, intruder just had to ask AWS patched Quick auth bypass, says customers weren't using control Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files US bank reports itself after slinging customer data at 'unauthorized AI app' Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime 'CopyFail' attackers start cashing in on Linux flaw ShinyHunters claims dump puts 119K Vimeo emails in the wild
No honor among thieves as 0APT threatens rival ransomware...
2026-04-14 · via The Register - Security

Two rival ransomware gangs have locked horns after 0APT threatened to expose people affiliated with Krybit.

Dark web watchers spotted the move on Sunday, though 0APT's motive for extorting a fellow criminal outfit remains unclear. The notion seems even more bizarre given that 0APT hypocritically described Krybit in its leak blog post as a ransomware group, and that "such groups pose significant risks to cybersecurity and data privacy worldwide."

"If the group does not make the payment or contact us, we will reveal their identity photos, names, location, and other," 0APT said. "And if you are one of their victims, contact us to get your data unlocked."

Following the standard double-extortion playbook, 0APT leaked a sample of the allegedly stolen Krybit data as a warning shot, threatening a full dump if payment isn't made.

The tactic loses much of its sting when aimed at criminals rather than businesses. Ransomware operators typically rely on the threat of reputational damage to coerce victims, leverage that evaporates when the target has no reputation worth protecting. The model is, in this context, almost laughably toothless.

That said, cybercriminals are famously paranoid about their identities for good reason, which gives the threat at least some residual bite.

Eric Taylor, owner of South Carolina security shop Barricade Cyber Solutions, said his team downloaded the small number of Krybit files already leaked by 0APT.

His team found plaintext credentials belonging to Krybit operators and affiliates, five cryptocurrency wallet addresses, and no evidence of a single paid ransom, among other things, he said.

Krybit's website is currently down, replaced by a splash page reading: "Everything will return to work shortly. We apologize for this. We are sorry for the inconvenience."

0APT launched in January 2026. According to Halcyon's ransomware research center, it "poses a legitimate threat" and shows "credible technical depth."

Within the first 48 hours of life, however, 0APT posted hundreds of victim organizations to its leak blog, a list that almost certainly included inflated victim claims, Halcyon said.

Krybit is less well-documented. No major threat intelligence or cybersecurity outfit has published a report on the group, and dark web tracking platforms suggest it has only been active for a few weeks, based on its recently claimed victims.

Criminal-on-criminal attacks aren't without precedent. DragonForce, for example, notably attacked rival groups BlackLock and Mamona in 2025, defacing their websites and leaking some internal communications.

DragonForce also seemingly took over and later shut down former ransomware kingpin RansomHub's operation in April last year after a month of infighting between the two criminal enterprises. ®