DataBreachPlus is a financially motivated cybercriminal operator identity associated with a malware-as-a-service operation centered on the CRPX0 ransomware component and a broader multi-function toolset. The operation has been linked to a commercialized platform offering multiple monetization paths, including ransomware extortion, cryptocurrency clipboard hijacking, seed phrase theft, and broader infostealer-style collection of browser data, wallet material, messaging data, screenshots, logs, and backup codes. The branding DataBreachPlus is used specifically for ransom negotiation and extortion communications, while CRPX0 refers to the ransomware module itself. The operation targets Windows, macOS, and Linux, with delivery observed through social-engineering lures themed around shipping notifications and adult-content account lists. On macOS, the actor has used builder scripts and packaging chains involving AppleScript applets, installer packages, encrypted disk images, native binaries, and encoded shell loaders to bypass user trust controls. Persistence has been established on macOS through LaunchAgents and on Windows through Run-key and scheduled-task mechanisms. The CRPX0 ransomware encrypts victim files and deploys multilingual ransom notes in English, Russian, and Chinese. It also performs recovery inhibition by deleting or disabling local backup artifacts such as shadow copies and snapshots across supported operating systems, and it changes the victim desktop wallpaper after encryption. The malware sends encryption material to operator-controlled infrastructure before or during the encryption workflow. Beyond ransomware, the broader service includes a clipper that monitors clipboard contents and substitutes cryptocurrency wallet addresses, as well as a BIP39 seed phrase scanner that searches victim files for wallet recovery phrases and exfiltrates discovered material. Exposed panel functionality also indicated credential and session-data theft from browsers and applications, including cookies and other account artifacts. The platform appears to have been operated as a license-based MaaS offering with tiered access, suggesting either a single operator selling access or a small criminal team supporting affiliates or customers. Infrastructure, language use, and operational artifacts indicate a likely Russian-speaking nexus. Russian-language ransom notes and use of Russian hosting and notification infrastructure support that assessment, although direct state affiliation is not supported. DataBreachPlus is best characterized as a cybercriminal extortion and theft actor rather than a nation-state group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
38 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Emerging ransomware-as-a-service identity tied to a broader TwizAdmin MaaS operation that combines cryptocurrency clipboard hijacking, BIP-39 seed phrase theft, browser cookie/credential exfiltration, and on-demand ransomware deployment against Windows and macOS victims.
Operates a commercial Malware-as-a-Service operation internally branded CRPX0 that combines a cryptocurrency clipboard hijacker, a seed phrase scanner/stealer, and a cross-platform ransomware module managed through a centralized PHP dashboard.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.