Multiple reports say the ransomware groups 0APT and KryBit become involved in a public dispute in which each side discloses information about the other. The conflict centers on each group posting or leaking data connected to the rival’s operations, including infrastructure and operational details. One account describes the escalation as attacks between the two groups, after which information is exposed that can help defenders understand how the groups work.

Across the sources, the central theme is that the rivalry results in “leaks” that provide third parties with visibility into ransomware activity rather than information remaining solely internal between the criminals. The disclosed material is described as doxxing- and infrastructure-related, suggesting that the postings include identifiers or details tied to the groups’ technical and operational presence. While the reports do not provide consistent specifics on the size of the leak, the exact contents, or the methods used to collect the information, they agree that the public exchange of data is unusual and gives defenders an opportunity to learn more about ransomware operations and infrastructure.