AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups — Threadlinqs Intelligence
As of 2026-07-29, AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups is a medium-severity ransomware threat attributed to 0APT, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1761 · Severity: MEDIUM · Status: ACTIVE · Category: RANSOMWARE
Attribution: 0APT · FINANCIAL
Recorded Future's Insikt Group documents an evolution in extortion tactics in which threat actors stand up fake Tor data-leak sites and AI-generated victim lists to extort enterprises without
In late January 2026 a previously unknown group calling itself 0APT launched a Tor-based data-leak site (DLS) at oaptxiyisljt2kv3we2we34kuudmqda7f2geffoylzpeo7ourhtz4dad.onion and, within about a week, claimed to have breached more than 150-253 organizations, listing 61 named victims by February 5, 2026. Independent analysis by Intel 471, GuidePoint's GRIT, Halcyon, and ReliaQuest converged on the same conclusion: the overwhelming majority of the claimed victims are fabricated. Uploaded 'proof' files were oversized (multi-gigabyte) but consisted of repeating null bytes or content piped from /dev/random directly into the browser, making them functionally undownloadable over Tor and impossible to verify. Several posted victims were generic, LLM-plausible company names (e.g., 'Metropolis City Municipal') mixed in with recognizable real organizations that had not actually been breached. Source-code artifacts contained comments in Hindi and Urdu, an attribution signal pointing away from the typical Russia/CIS ransomware center of gravity toward Southern Asia. 0APT also ran a ransomware-as-a-service (RaaS) affiliate program, initially charging a 1 BTC 'security bond' for onboarding (later dropped after backlash), a fraud structure resembling the 2024 'Mogilevich' affiliate-fee scam. Despite the fabricated victim roster, forensic teardown of the actual 0APT encryptor (Rust-based, ~5.6MB Windows PE / ~1.3MB Linux ELF, compiled with rustc/Visual C++ and gcc respectively) found a cryptographically robust and fully operational ransomware payload using AES-256 for file encryption, RSA-4096 (OpenSSL) for key wrapping, and additional stream-cipher support (ChaCha20/Salsa20, Speck, RC4 PRGA) — the Speck cipher choice drew comparisons to PromptLock, a previously identified AI-generated ransomware strain, reinforcing the assessment that 0APT's code itself may be partially AI-assisted. The encryptor verifies available RAM before encrypting each file, supports operator-configurable exclusion lists and thread counts via config2.txt, appends a .0apt/.0Apt extension, and drops a README0Apt.txt ransom note; a notable implementation bug means the ransom note itself can be accidentally encrypted if the operator's exclusion list isn't lowercase-normalized. On February 8, 2026 the DLS went dark after coordinated researcher scrutiny and returned a day later with a drastically pared-down list of ~15 multinational victims. On April 13, 2026 0APT published the leaked database of a rival operation, Krybit, in an apparent feud — the group's first verified real breach after months of fabrication. Separately, on March 22, 2026, a Tor site branding itself ALP-001 ('Data Leaks / Access Market') emerged, representing the pivot of a long-running initial access broker — tracked across Exploit and DarkForums since at least July 2024 under the aliases 'Alpha Group' and 'DGJT Group' — from selling perimeter-device access (FTP, SSH, Fortinet/FortiGate, Cisco, Citrix/RDWeb, Palo Alto GlobalProtect) into direct data-leak extortion. ALP-001 listed 17 named victims (Pellenc, Hikvision, JAXA, Iliad, Esprinet, and others) across 11 countries, but researchers found most claims unverifiable, some leaked material traced to misconfigured public FTP servers rather than genuine intrusions, and the operator cycled between forum handles as credibility was challenged; a matching Tox/Session ID and a prior January 2026 access-sale listing for Pellenc gave researchers confident attribution of the DLS to the known IAB account, even though the extortion claims themselves remain largely unsubstantiated. Both cases illustrate a broader Q1 2026 trend (2,638 ransomware/extortion posts across a record 91 active leak sites, up 22% year over year) in which the barrier to mounting a plausible-looking extortion campaign has collapsed: an actor with LLM access, a Tor hidden service, and a handful of scraped or purchased datasets can generate a leak site that is operationally indistinguishable from
Target sectors: health, professional services, technology, transportation and logistics, energy, manufacturing, finance, banking, critical infrastructure
Target regions: united states of america, france, germany, slovakia, poland, brazil, japan, italy, china, united kingdom, canada, spain
Related threats
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)
- FortiBleed Credential-Harvesting Campaign Against 430,000 FortiGate Firewalls Feeds INC Ransom and Lynx Ransomware Operations
- Ransomware Groups Exploit Citrix Bleed 2 (CVE-2025-5777) and Kontron Driver BYOVD for Access and Privilege Escalation
- Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) Ransom
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
4 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, MEDIUM, threat intelligence, cybersecurity, T1589, T1596, T1583.001, T1585.001, T1608.001, T1190, T1133, T1199, T1078, T1059