The CRPx0 cybercrime operation has expanded from a scam service into a ransomware-as-a-service, cryptocurrency-theft, and white-label intrusion platform. Affiliates use ClickFix social-engineering pages impersonating Windows or macOS updates and Google reCAPTCHA to persuade targets to run malicious commands. On Windows, the reported chain uses clipboard-delivered PowerShell, encrypted DLL loaders, and a Python bootstrap; macOS victims may receive a portable Python environment and the ransomware payload directly.
CRPx0 steals high-value data before encryption, attempts lateral movement, disables security controls, deletes backups, establishes persistence, and encrypts files with the .crpx0 extension. Victims reportedly receive 48 hours to pay before stolen data is threatened with publication. The operation uses a clearnet PHP relay to proxy communications to Tor infrastructure and claims 47 victims, mainly in the United States and Turkey. Defenders should restrict ClickFix-prone execution paths, investigate suspicious RunMRU entries and pre-encryption exfiltration, block validated network indicators, and ensure backups cannot be accessed using compromised credentials.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
CRPx0 published a v3.0 update note advertising a web-based control center for compromised systems. The advertised capabilities included file, credential, cryptocurrency recovery-phrase, and private-key theft, as well as remote command execution.
CRPx0 reportedly launched an affiliate program with a US$333 entry fee, a 70/30 revenue split favoring affiliates, Monero payment preference, and restrictions against targeting CIS countries.
CRPx0 was reported as active from June 2026, operating ransomware, cryptocurrency theft, and hacking-as-a-service offerings. Its clear-web leak site reportedly listed fewer than 10 organizations during the month.
The reporting identified the same TOX ID used by CRPX0 on flash-token.shop, a service advertising temporary synthetic cryptocurrency assets. The shared identifier was assessed as direct evidence associating CRPX0 with the Flash Token scam operation.
Ransom-ISAC published a technical analysis detailing CRPx0's ClickFix delivery chains, Python ransomware payload, pre-encryption theft, security-control evasion, persistence, backup deletion, encryption, and lateral-movement capabilities. The report also identified network, header, token, file, and persistence artifacts, while cautioning that automatically extracted IOCs require validation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 71 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourceransom-isac.org
Open sourcecyberveille.ch
Open sourcetheravenfile.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.