CRPX0 is a multi-stage, financially motivated malware suite and ransomware operation targeting Windows and macOS, with multiple reports indicating cross-platform ransomware support for Linux as well. The operation combines several monetization functions: a cryptocurrency clipboard hijacker/clipper, a BIP39 seed phrase scanner and stealer, broader credential and data theft, and a ransomware module used for double extortion. Delivery has been observed through social-engineering lures such as fake OnlyFans account archives and fake FedEx shipping documents. In reported infection chains, victims download a malicious ZIP archive containing a disguised shortcut that executes hidden commands, followed by a VBScript loader and Python-based payloads that connect to a remote server for interactive control, updates, and deployment of additional components.
The crypto theft components monitor clipboard contents for wallet addresses and recovery phrases, replacing copied wallet addresses with attacker-controlled addresses and exfiltrating discovered seed phrases. Reported supported cryptocurrencies include Bitcoin, Ethereum, Tron, Dogecoin, Litecoin, Solana, XRP/Ripple, and Bitcoin Cash, with support for multiple Bitcoin address formats. The seed-finder component scans victim files for 12-word and 24-word BIP39 recovery phrases and exfiltrates matches to the command infrastructure. Reporting also ties the broader operation to infostealer functionality including theft of browser cookies, Discord tokens, Telegram sessions, Steam and Minecraft credentials, 2FA backup codes, screenshots, and other harvested data.
The ransomware component, identified as crypter.py, uses Python Fernet-based encryption, appends the .crpx0 extension to encrypted files, drops ransom notes named HOW TO RECOVER.txt in English, Russian, and Chinese, and changes the victim wallpaper after encryption. It is reported to delete recovery artifacts including Windows shadow copies and macOS/Linux snapshots using utilities such as vssadmin, wmic, wbadmin, tmutil, and timeshift. The campaign has been described as using data exfiltration before or during encryption, targeting documents, media, emails, code, and other sensitive files to support extortion.
The operation is associated with the ransomware-as-a-service identity DataBreachPlus and exposed infrastructure including fanonlyatn[.]xyz as a primary panel/C2 domain, with backup ransomware notification domains caribb[.]ru, mekhovaya-shuba[.]ru, and beboss34[.]ru resolving to 31.31.198[.]206 on REG.RU infrastructure. Reported operator contact channels include Telegram handle @DataBreachPlus, ProtonMail address databreachplus@proton[.]me, and qTox ID 17EB54B8455144E088C7E77F88A97221C319F0CFE4FE306853EEB113EE8DB5607BB6EE481C7C. Additional reported indicators and artifacts include the hardcoded dashboard API secret 26i$MyYe@r, the loader/access password pass2021#, persistence via macOS LaunchAgents such as ~/Library/LaunchAgents/com.sys32.data.plist and com.cryptoprice.guard.plist, Windows persistence via the HKCU Run key CryptoGuard and scheduled task CryptoUpdate, and working directories such as ~/.sys32data and %APPDATA%\sys32data. Reporting assesses the actor as likely Russian-speaking and financially motivated, operating CRPX0 as a MaaS/RaaS-style platform.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The ransomware component communicates with three Russian .ru domains and uses the ransomware-as-a-service identity "DataBreachPlus" with Telegram, qTox, and ProtonMail contact channels.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK Mapping ... Execution Command and Scripting Interpreter: Unix Shell T1059.004 Bash loaders (macOS)
MITRE ATT&CK Mapping ... Execution Command and Scripting Interpreter: Visual Basic T1059.005 VBS launchers (Windows)
MITRE ATT&CK Mapping ... Execution Command and Scripting Interpreter: Python T1059.006 All payloads are Python
Following data theft, the malware encrypts targeted files with the .crpx0 extension, displays a "gotcha" image as the desktop wallpaper, and drops ransom notes in multiple languages.
MITRE ATT&CK Mapping ... Impact Inhibit System Recovery T1490 Shadow copy deletion
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-platform malware campaign that uses social engineering to infect victims, steals cryptocurrency by monitoring and altering clipboard wallet addresses, exfiltrates documents/media/emails/code files, and then encrypts files with a .crpx0 extension as part of a double-extortion ransomware operation.
Ransomware delivered via a ZIP file in a lure themed around 'free OnlyFans accounts'; the campaign uses a multi-stage execution chain with a malicious shortcut, VBScript loader, Python-based components, remote command capability, credential/data theft, and eventual file encryption plus data exfiltration.
crpx0 is the ransomware module in the TwizAdmin operation. It encrypts files with the .crpx0 extension using Python cryptography.fernet.Fernet, drops ransom notes in English, Russian, and Chinese, inventories files, and notifies backend infrastructure hosted on multiple Russian domains.
A three-component malware suite focused on cryptocurrency theft and extortion. It includes a clipboard hijacker that swaps copied wallet addresses and captures BIP39 seed phrases, a file scanner that searches victim systems for wallet recovery phrases, and a ransomware component that encrypts files with the .crpx0 extension and deletes Volume Shadow Copies on Windows.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.