Aryaka Threat Research Labs reported a multi-stage CRPx0 malware campaign that tricks users searching for “free OnlyFans accounts” into opening a malicious ZIP archive containing a disguised shortcut. The shortcut launches hidden commands and a VBScript loader that prepares the host, installs components for Python-based malware, and connects to a remote server for interactive attacker control. Researchers said the operation targets Windows and macOS, with possible Linux support in development, and is built to blend into normal user behavior rather than rely on a single obvious malicious action.
Once active, the malware supports clipboard-based cryptocurrency theft, credential and data harvesting, system reconnaissance, selective exfiltration, and eventual ransomware deployment in a double-extortion scheme. Stolen content reportedly includes documents, media, emails, and source code before files are encrypted with the .crpx0 extension; the malware then changes the desktop wallpaper to a “gotcha” image and drops multilingual ransom notes directing victims to contact the operators via email, qTox, and Telegram. Reporting also said the group runs a leak site claiming 38 victims and more than 10,839 TB of leaked data, while offering access to stolen information for $500 in cryptocurrency.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
The operators maintained a leak site claiming 38 victims and more than 10,839 terabytes of leaked data, and reportedly offered access to stolen data for $500 in cryptocurrency. Victims were instructed to contact the attackers via email, qTox, and Telegram.
Aryaka Threat Research Labs publicly reported the multi-stage CRPx0 campaign and detailed how the lure, loaders, Python malware, data theft, and ransomware stages worked. The report emphasized the campaign's layered, adaptive behavior and the organizational risk posed by personal browsing activity.
After execution, the infection chain used hidden commands, a VBScript loader, and Python-based malware to establish remote control, perform reconnaissance, steal credentials and data, hijack cryptocurrency clipboard activity, and exfiltrate files. The attackers then deployed CRPx0 ransomware, encrypted files with the .crpx0 extension, changed the wallpaper, and dropped multilingual ransom notes as part of a double-extortion scheme.
Threat actors began distributing a multi-stage malware campaign using lures for "free OnlyFans accounts" to trick users into downloading a malicious ZIP archive containing a disguised shortcut file. The campaign targeted Windows and macOS systems, with possible Linux support reportedly under development.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.