News Room
16
Share
0APT Ransomware Surge: Threat Actor Executes 100 Daily Attacks Targeting Global IT Supply Chains
criticalThreat Intelligence

0APT Ransomware Surge: Threat Actor Executes 100 Daily Attacks Targeting Global IT Supply Chains

The 0APT ransomware group has escalated operations, conducting nearly 100 attacks in 24 hours. Recent breaches include TechnoSoft Services, signaling a strategic shift toward IT service provider exploitation.

16 August 2026Last updated 18 August 20265 min readRansom-DB / Mandiant Intelligence
E
Encrygma AI Cyber Weapons Advisory Services :We sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
Critical
Actor Type:
Ransomware Group
Geography:
Global
Confidence:
High Confidence
CVE:
CVE-2026-68820
Source:
Ransom-DB / Mandiant Intelligence
Read Time:
5 min

Executive Summary

As of August 16, 2026, Encrygma intelligence has tracked a significant escalation in ransomware activity, primarily driven by the 0APT group. In a single 24-hour period, the group has been linked to nearly 100 distinct attacks, demonstrating an unprecedented operational scale. Simultaneously, the Qilin ransomware group has claimed a high-profile breach of the ASCII Group in Japan, while the Russia-linked Cl0p group has initiated a fresh wave of extortion against multinational entities including Shell and Philips. This surge underscores a volatile threat landscape where high-volume 'spray and pray' tactics are being combined with surgical supply chain strikes.

Threat Analysis

The 0APT group represents a departure from traditional ransomware-as-a-service (RaaS) models that focus on a few high-value targets per week. Their current campaign suggests a highly automated infrastructure capable of managing dozens of concurrent negotiations. The most concerning development is 0APT's pivot toward IT service providers, such as the recently confirmed breach of TechnoSoft Services. By compromising managed service providers (MSPs) and IT consultants, 0APT gains downstream access to hundreds of client networks, effectively turning a single intrusion into a force multiplier for extortion.

Technical Details

Recent telemetry indicates that 0APT and contemporary groups like 'The Gentlemen' are increasingly deploying advanced EDR (Endpoint Detection and Response) kill techniques. These actors are systematically reverse-engineering samples from older variants like Babuk and LockBit 5.0 to develop custom drivers that terminate security processes before encryption begins. Furthermore, intelligence from CISA and international partners suggests that the Gunra ransomware variant is currently exploiting critical vulnerabilities in Fortinet FortiOS and FortiProxy (CVE-2026-68820) to gain initial access. Once inside, actors utilize a double-extortion model, exfiltrating sensitive data to dedicated leak sites (DLS) within a 72-minute window—a speed that significantly outpaces traditional incident response capabilities.

Attribution Assessment

While 0APT's origins remain obscured by sophisticated proxy usage, their technical proficiency and operational tempo suggest a well-funded cybercriminal collective, likely operating out of Eastern Europe or a CIS-affiliated region. The group does not appear to be restricted by industry or geography, though their recent focus on Japanese (ASCII Group) and U.S. critical infrastructure (Southern Metals Company) indicates a preference for regions with high insurance payout potential. The use of 'The Gentlemen' ransomware samples suggests a collaborative ecosystem where code and exploits are shared across the dark web.

Implications

The shift toward IT supply chain exploitation means that even organizations with robust internal perimeters are at risk through their third-party vendors. The speed of data exfiltration (under 90 minutes) renders reactive security measures nearly obsolete. Furthermore, the re-emergence of Cl0p targeting global conglomerates like Shell and Philips indicates that 'big game hunting' remains a primary motivator for established actors, even as newer groups like 0APT focus on volume.

Recommendations

Encrygma recommends that organizations immediately audit all internet-facing Fortinet appliances and apply the latest security patches. Strict multi-factor authentication (MFA) must be enforced for all remote access points, particularly for third-party IT service providers. Security teams should implement immutable, offline backups to ensure recovery in the event of successful encryption. Finally, organizations must transition to a 'Zero Trust' architecture that assumes perimeter breach and focuses on limiting lateral movement and data egress through real-time monitoring of unusual traffic spikes.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo