CRPx0 is a financially motivated cybercrime operation active since June 2026 that operates a ransomware-as-a-service platform alongside cryptocurrency-theft and white-label intrusion services. The operation supplies affiliates with customizable payloads, command-and-control infrastructure, negotiation capabilities, and leak-site support. Its affiliate model has included revenue sharing and restrictions against targeting Commonwealth of Independent States organizations. CRPx0 primarily uses ClickFix social-engineering lures masquerading as software updates or CAPTCHA verification to induce victims to execute attacker-provided commands on Windows or macOS. It also distributes standalone payload formats. The multi-stage delivery chain deploys a cross-platform Python ransomware payload and includes anti-analysis checks, endpoint-defense evasion through security-tool tampering and API unhooking, privilege-escalation attempts, and persistence on Windows and macOS. The malware performs network and domain reconnaissance, can move laterally using remote administration and network-share mechanisms, deletes or inhibits backups, and exfiltrates selected business documents and credential-bearing material before encryption. It also supports cryptocurrency theft, including clipboard hijacking and collection of wallet recovery material and private keys. CRPx0 encrypts local and network-accessible data, then threatens public release or sale of stolen information if victims do not pay within a short deadline. The group operates a leak site and has claimed victims predominantly in the United States and Turkey, particularly in healthcare and financial services; individual victim claims remain unverified.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
31 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A ransomware-as-a-service operation that uses affiliates to conduct cryptocurrency theft, data exfiltration, and network-wide file encryption. It is reported to employ ClickFix social-engineering lures, clipboard cryptocurrency-address substitution, theft of passwords and wallet recovery phrases, and 48-hour double-extortion demands.
Operates a ransomware, data-theft, cryptocurrency-theft, and network-compromise service for affiliates. It provides ClickFix lures, command-and-control infrastructure, negotiation panels, malware, and a web-based control center. Its ransomware steals high-value files, encrypts files, and threatens public leakage.
Ransomware-as-a-service operation offering affiliate-customized ClickFix lures and standalone payloads. It conducts pre-encryption data theft, credential-material collection, file encryption, double extortion, backup destruction, endpoint-defense evasion, and Windows domain/macOS-Linux propagation. The operation also markets a CRPx0 COMMAND panel and v3.0 white-label crimeware platform.
Ransomware-as-a-service operation using ClickFix lures, HTML smuggling, standalone DLL/EXE payloads, and macOS droppers to deploy a Python ransomware payload. It exfiltrates data before encryption, encrypts files using Fernet keys wrapped with RSA-4096, destroys backups, disables security tooling, establishes persistence, performs UAC bypass, and propagates laterally over domain networks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.