Researchers found an open directory and management panel tied to the CRPX0 malware operation at fanonlyatn[.]xyz, exposing the full source code, backend infrastructure, and operator details for a malware-as-a-service platform. The leaked materials showed a three-part criminal toolkit: a cryptocurrency clipboard hijacker supporting 10 coins, a BIP39 seed-phrase scanner and stealer, and ransomware for Windows, macOS, and Linux that appends the .crpx0 extension. The code and panel also exposed plaintext secrets, including a shared dashboard API secret, a loader password, ten hardcoded wallet addresses, and contact points linked to the operator, including the Telegram handle @DataBreachPlus, databreachplus@proton[.]me, and a qTox ID.
Analysis of the leaked infrastructure tied the operation to backup command-and-control and ransom-notification domains hosted on 31[.]31[.]198[.]206 through REG.RU, while the primary panel sat behind Cloudflare. The exposed files showed Windows routines to delete Volume Shadow Copies, macOS builder scripts aimed at bypassing Gatekeeper, and lures themed around fake FedEx shipping notices and fake OnlyFans account lists. Researchers also identified a separate exposed TwizAdmin panel at 103.241.66[.]238:1337 that pointed to additional infostealer functionality and suggested the campaign has been active since at least July 2025; one unusual artifact was ransomware wallpaper containing C2PA metadata indicating it had been generated with ChatGPT/GPT-4.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Researchers analyzed an active multi-vector malware campaign delivering XWorm V6.0 and linked it with moderate confidence to a Turkish-speaking threat actor. The attribution was based on a public GitHub staging repository, Turkish-language filenames, and a GitHub commit email address.
Researchers identified a separate exposed TwizAdmin panel at 103.241.66[.]238:1337 linked to the CRPX0 operation. This panel confirmed additional infostealer functionality beyond the clipper, seed theft, and ransomware modules.
The exposed CRPX0 files revealed plaintext secrets including a dashboard API secret, loader password, ten hardcoded cryptocurrency wallet addresses, and operator contact details such as @DataBreachPlus and databreachplus@proton[.]me. Infrastructure analysis also tied backup C2 and notification domains to REG.RU-hosted systems at 31[.]31[.]198[.]206.
Breakglass Intelligence found an exposed panel at fanonlyatn[.]xyz that revealed the full source code and infrastructure for the CRPX0 malware-as-a-service operation. The leak exposed a centralized PHP dashboard, open self-registration, payment-code controls, and multi-platform malware components for Windows, macOS, and Linux.
Analysis of the exposed CRPX0 infrastructure indicated the malware operation had been active since at least July 2025. The campaign combined crypto clipping, seed phrase theft, and ransomware capabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 31 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
intel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceintel.breakglass.tech
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.