CRPx0 is a cross-platform ransomware family and ransomware-as-a-service offering associated with the DataBreachPlus branding. It targets Windows, macOS, and Linux systems through ClickFix social-engineering lures and standalone payloads. ClickFix campaigns impersonate software updates or CAPTCHA verification and induce victims to execute attacker-supplied commands. Earlier campaigns also used fraudulent shipping-document and adult-content lures distributed in archives.
CRPx0 uses staged loaders to deploy a Python-based ransomware payload. It performs anti-analysis and endpoint-defense evasion, including attempts to impair security tooling and bypass User Account Control on Windows. The malware establishes persistence, deletes or degrades backup and recovery mechanisms, conducts host, domain, and network-share reconnaissance, and can attempt lateral movement through remote administration and network-share mechanisms.
Before encryption, CRPx0 collects and exfiltrates selected documents and credential-bearing material, including cryptocurrency-wallet recovery phrases, private keys, certificates, password-manager data, application secrets, and VPN configuration. Its cryptocurrency-theft components monitor the clipboard and substitute cryptocurrency wallet addresses, and scan victim files for recovery phrases. The ransomware uses per-victim symmetric encryption keys protected with embedded asymmetric cryptography, may partially encrypt large files, and delivers ransom demands threatening publication or sale of stolen data. The operation is marketed to affiliates as a commercial criminal service and combines data theft, cryptocurrency theft, and double-extortion ransomware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The article analyzes the CRPX0 ransomware program and affiliate panel, including generated payload behavior and the v3.0 feature set.
The ransomware component communicates with three Russian .ru domains and uses the ransomware-as-a-service identity "DataBreachPlus" with Telegram, qTox, and ProtonMail contact channels.
43 distinct techniques documented for this family, organized by ATT&CK tactic.
The propagation routine runs wmic /node:<target> process call create to execute the copied payload remotely. | wmic process call create in domain_encrypt_network() ... for lateral execution.
establish_persistence() creates an on-logon scheduled task named OneDrive Sync Maintenance; lateral propagation also creates OneDrive Maintenance tasks on remote hosts. | schtasks /create /tn "OneDrive Sync Maintenance" /sc ONLOGON; remote hosts use "OneDrive Maintenance."
powershell -w h -enc [base64] ... downloads the stager DLL and saves it as WindowsUpdate.log. | Windows victims execute a clipboard-injected powershell -w h -enc command that downloads and launches the DLL stager.
On macOS, a curl | bash one-liner downloads portable Python and sys_core_*.bin, then runs the ransomware.
Final payload is sys_service.py ... macOS path downloads standalone Python 3.10.13 to execute it.
Victim pastes clipboard via Win+R (Windows) or Cmd+V in Terminal (macOS) following fake verification steps.
establish_persistence() creates an on-logon scheduled task named OneDrive Sync Maintenance; lateral propagation also creates OneDrive Maintenance tasks on remote hosts. | schtasks /create /tn "OneDrive Sync Maintenance" /sc ONLOGON; remote hosts use "OneDrive Maintenance."
establish_persistence() creates an on-logon scheduled task named OneDrive Sync Maintenance; lateral propagation also creates OneDrive Maintenance tasks on remote hosts. | schtasks /create /tn "OneDrive Sync Maintenance" /sc ONLOGON; remote hosts use "OneDrive Maintenance."
inject_into_explorer(): CreateRemoteThread into explorer.exe to break the parent-child process chain. | The ransomware includes inject_into_explorer(), described as using CreateRemoteThread into explorer.exe to break the parent-child process chain.
4 layers: XOR+ROL+NOT (DLL stager), XOR config/bootstrap encoding, and chr() import hiding. | The outer lure uses document.write(atob(...)); DLL payloads use XOR+ROL+NOT encryption; configuration and Python payloads are XOR-, Base64-, and zlib-obfuscated.
Outer HTML is single line: document.write(atob('...')) — entire 5.3 MB page base64-encoded.
Payloads use names such as WindowsUpdate.log, data.dll, sys_<hex8>, and legitimate-looking staging directories including Windows_Driver_Host and Cache_Sys. | data.dll .rsrc: fake version info mixing Oracle, Microsoft and Intel; task name "OneDrive Sync Maintenance."
inject_into_explorer(): CreateRemoteThread into explorer.exe to break the parent-child process chain. | The ransomware includes inject_into_explorer(), described as using CreateRemoteThread into explorer.exe to break the parent-child process chain.
self_destruct() ... VBS script overwrites own file with random bytes then deletes. | self_destruct() launches delayed VBS or shell cleanup that overwrites payload files or staging directories and deletes them along with the cleanup script.
dx() XOR-decodes config at runtime ... _init_crypto() Fernet-decrypts the key itself.
The PowerShell command saves the stager as WindowsUpdate.log and executes it via rundll32 by ordinal.
domain_encrypt_network() obtains domain-controller and server information, ARP cache data, and performs a local /24 subnet scan.
platform.system(), os.name, uname -m ... for OS/arch detection throughout all phases.
stage1_scan(): recursive os.walk() full-disk file discovery with extension-based targeting and exclusion dirs.
The payload uses net view /domain and net view \\<target> to enumerate domain servers and reachable remote shares.
nltest /domain_trusts and net view /domain for domain enumeration.
UNC path enumeration and encryption of files on \\host\share network shares. | The payload checks TCP/445, enumerates shares, encrypts files over UNC paths, and copies itself to \\<target>\C$\Windows\Temp.
Before encryption, the payload collects office documents and high-value files such as .kdbx, .pem, .pfx, .env, .ovpn, and .keystore files. | 5 random docs + 10 high-value files, zipped and chunked multipart upload to C2.
silentCopy() and silentCopyHelloWorld() write the OS-specific malicious command to the victim clipboard before instructions are displayed. | silentCopy() / navigator.clipboard.writeText() in ClickFix HTML — hijacks clipboard with OS-specific payload command.
JSON POST with Authorization: Bearer crpx0_c2_2026 ... clearnet then Tor fallback. | Stage 4 sends JSON status beacons and multipart exfiltration requests to /relay.php using Authorization: Bearer crpx0_c2_2026.
The clearnet PHP relay forwards traffic through Tor SOCKS5 to the .onion C2 backend.
Stage 3 downloads the embeddable Python distribution and get-pip.py, then pip installs cryptography, requests and pywin32. | The loader downloads embedded Python from python.org, get-pip.py from bootstrap.pypa.io, and the macOS path retrieves sys_core_*.bin from relay.php.
stage2_encrypt(): Fernet.generate_key() per victim, RSA-4096 OAEP key wrapping, ThreadPoolExecutor. | stage2_encrypt() generates a per-victim Fernet key, encrypts the first 1 MB of targeted files, appends .crpx0, deletes originals, and drops ransom notes.
remove_backups() invokes vssadmin delete shadows, wmic shadowcopy delete, wbadmin delete catalog, tmutil thinlocalsnapshots, or timeshift --delete-all before file encryption. | remove_backups(): vssadmin delete shadows, wmic shadowcopy delete, wbadmin delete catalog; tmutil delete (Mac).
The ransomware unhooks ntdll, patches AmsiScanBuffer and EtwEventWrite, and kills or deletes AV/EDR processes and services. | patch_amsi() patches AmsiScanBuffer; patch_etw() patches EtwEventWrite; unhook_ntdll() overwrites the in-memory .text section to strip EDR hooks.
94 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware-as-a-service operation with cryptocurrency theft capabilities. It uses clipboard hijacking to replace copied cryptocurrency wallet addresses with attacker-controlled addresses, exfiltrates passwords, wallet recovery phrases and other valuable data, then encrypts files across the network and threatens to leak stolen data unless a ransom is paid within 48 hours. Initial access commonly relies on ClickFix social engineering.
Cross-platform ransomware operated and marketed as a RaaS platform. It uses ClickFix fake-update and reCAPTCHA lures, as well as standalone DLL/EXE and macOS bash delivery formats. The payload performs anti-analysis and security-tool evasion, establishes persistence, attempts UAC bypass and lateral movement, destroys backups, exfiltrates documents and credential material before encryption, encrypts the first 1 MB of targeted files with a per-victim Fernet key wrapped using RSA-4096, appends the .crpx0 extension, and deploys ransom notes.
Cross-platform, Python-based ransomware-as-a-service operation. It uses HTML-smuggling ClickFix lures, malicious clipboard commands, DLL stagers/loaders, and alternate standalone DLL/EXE delivery. It conducts system and domain reconnaissance, collects and exfiltrates high-value files and credentials, attempts UAC bypass and security-tool termination, deletes backups and shadow copies, establishes scheduled-task or macOS LaunchAgent persistence, propagates laterally through SMB/WMI/scheduled tasks/GPO/SSH, encrypts data, and threatens publication of stolen data.
Cross-platform Python ransomware operation delivered through ClickFix lures. It performs anti-analysis, AMSI/ETW evasion, UAC bypass, persistence, security-tool and backup destruction, limited pre-encryption data exfiltration, lateral movement, AES-128-CBC file encryption with RSA-4096-OAEP key wrapping, and appends the .crpx0 extension.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.