APT73 — Ransomware Profile

APT73 surfaced in April 2024, standing up a leak site on 25 April whose layout copied LockBit's closely enough that Malpedia records the imitation as a bid for credibility among criminal peers. Malpedia describes the operation as the work of a suspected former LockBit affiliate who split off after Operation Cronos, the February 2024 law-enforcement seizure of LockBit infrastructure, and QuoIntelligence covered it in June 2024 as part of the post-takedown reshuffling of the extortion market. The crew adopted "APT" — the industry's shorthand for state-linked advanced persistent threat actors — as a self-applied badge despite running as a financially motivated ransomware-as-a-service brand, and later rebranded to Bashe, the name under which ransomware.live now tracks it. That tracker counts about 160 named victims spread over roughly 50 countries, led by the United States, the United Kingdom, Brazil, France and Germany, and concentrated in professional services, technology, financial services, government and defence, and healthcare. Listings continued into July 2026.

Also tracked as

Eraleign, Bashe, Eraleig

Recent claimed victims

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions