
0APT Ransomware Surge: Threat Actor Executes 100 Daily Attacks Targeting Global IT Supply Chains
The 0APT ransomware group has escalated operations, conducting nearly 100 attacks in 24 hours. Recent breaches include TechnoSoft Services, signaling a strategic shift toward IT service provider exploitation.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- Global
- Confidence:
- High Confidence
- CVE:
- CVE-2026-68820
- Source:
- Ransom-DB / Mandiant Intelligence
- Read Time:
- 5 min
Executive Summary
As of August 16, 2026, Encrygma intelligence has tracked a significant escalation in ransomware activity, primarily driven by the 0APT group. In a single 24-hour period, the group has been linked to nearly 100 distinct attacks, demonstrating an unprecedented operational scale. Simultaneously, the Qilin ransomware group has claimed a high-profile breach of the ASCII Group in Japan, while the Russia-linked Cl0p group has initiated a fresh wave of extortion against multinational entities including Shell and Philips. This surge underscores a volatile threat landscape where high-volume 'spray and pray' tactics are being combined with surgical supply chain strikes.
Threat Analysis
The 0APT group represents a departure from traditional ransomware-as-a-service (RaaS) models that focus on a few high-value targets per week. Their current campaign suggests a highly automated infrastructure capable of managing dozens of concurrent negotiations. The most concerning development is 0APT's pivot toward IT service providers, such as the recently confirmed breach of TechnoSoft Services. By compromising managed service providers (MSPs) and IT consultants, 0APT gains downstream access to hundreds of client networks, effectively turning a single intrusion into a force multiplier for extortion.
Technical Details
Recent telemetry indicates that 0APT and contemporary groups like 'The Gentlemen' are increasingly deploying advanced EDR (Endpoint Detection and Response) kill techniques. These actors are systematically reverse-engineering samples from older variants like Babuk and LockBit 5.0 to develop custom drivers that terminate security processes before encryption begins. Furthermore, intelligence from CISA and international partners suggests that the Gunra ransomware variant is currently exploiting critical vulnerabilities in Fortinet FortiOS and FortiProxy (CVE-2026-68820) to gain initial access. Once inside, actors utilize a double-extortion model, exfiltrating sensitive data to dedicated leak sites (DLS) within a 72-minute window—a speed that significantly outpaces traditional incident response capabilities.
Attribution Assessment
While 0APT's origins remain obscured by sophisticated proxy usage, their technical proficiency and operational tempo suggest a well-funded cybercriminal collective, likely operating out of Eastern Europe or a CIS-affiliated region. The group does not appear to be restricted by industry or geography, though their recent focus on Japanese (ASCII Group) and U.S. critical infrastructure (Southern Metals Company) indicates a preference for regions with high insurance payout potential. The use of 'The Gentlemen' ransomware samples suggests a collaborative ecosystem where code and exploits are shared across the dark web.
Implications
The shift toward IT supply chain exploitation means that even organizations with robust internal perimeters are at risk through their third-party vendors. The speed of data exfiltration (under 90 minutes) renders reactive security measures nearly obsolete. Furthermore, the re-emergence of Cl0p targeting global conglomerates like Shell and Philips indicates that 'big game hunting' remains a primary motivator for established actors, even as newer groups like 0APT focus on volume.
Recommendations
Encrygma recommends that organizations immediately audit all internet-facing Fortinet appliances and apply the latest security patches. Strict multi-factor authentication (MFA) must be enforced for all remote access points, particularly for third-party IT service providers. Security teams should implement immutable, offline backups to ensure recovery in the event of successful encryption. Finally, organizations must transition to a 'Zero Trust' architecture that assumes perimeter breach and focuses on limiting lateral movement and data egress through real-time monitoring of unusual traffic spikes.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Secp0 and Qilin Ransomware Groups Escalate Global Attacks on Real Estate and Electronics Sectors

Ransomware Surge: Record 1,073 Victims in August 2026 as ShinyHunters Targets Rival Clop Gang

