Skip to content

crpx0

CRPX0 is a financially motivated, cross-platform malware-as-a-service and ransomware-as-a-service operation active since at least 2025–2026.

Profile source: Mallory opens in a new tab

crpx0

Family profile

CRPX0 is a financially motivated, cross-platform malware-as-a-service and ransomware-as-a-service operation active since at least 2025–2026. The CRPX0 brand encompasses a Python-based ransomware component as well as cryptocurrency-focused theft tooling, including clipboard hijacking and BIP39 recovery-phrase discovery. The operation has been associated with the DataBreachPlus identity and an affiliate-oriented commercialization model.

CRPX0 targets Windows, macOS, and Linux systems. Delivery has used ClickFix social-engineering pages masquerading as software-update or CAPTCHA prompts that induce victims to execute clipboard-injected commands. Other observed lure themes include purported shipping documents and adult-content account lists, delivered through archives, malicious shortcuts, and standalone executable or DLL payloads. The staged Windows chain deploys a Python runtime and loader components; macOS delivery similarly deploys portable Python and an obfuscated loader.

The ransomware conducts anti-analysis and defense-evasion activity, including attempts to impair endpoint telemetry, unhook user-mode security instrumentation, terminate security products, and bypass UAC on Windows. It establishes persistence through scheduled tasks on Windows and LaunchAgents on macOS, deletes or degrades local recovery mechanisms, and can self-delete after execution. It performs host, domain, and network-share reconnaissance and supports propagation through remote administration mechanisms, SMB-accessible shares, remote scheduled tasks, WMI, domain policy startup scripts, and SSH-based logic.

Before encryption, CRPX0 collects selected documents and high-value credential material, including password-manager databases, keychain data, private keys, certificates, application secrets, VPN profiles, browser data, authentication tokens, and cryptocurrency recovery phrases. It packages and exfiltrates stolen data to support double extortion. The ransomware encrypts targeted local and reachable network files using per-victim symmetric encryption keys protected with embedded asymmetric cryptography, may use partial encryption for larger files, appends a CRPX0-specific extension, and leaves multilingual ransom notes demanding cryptocurrency payment. Operators threaten publication or sale of stolen data if payment deadlines are not met. Separately, the clipper component monitors and substitutes cryptocurrency wallet addresses in the clipboard, enabling theft of redirected transfers.

Capabilities

  • Credential Theft
  • Crypto Theft
  • Defense Evasion
  • Exfiltration
  • Initial Access
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Privilege Escalation
  • Reconnaissance
  • Session Hijacking

Reported operators

Threat actors

2 named in public reporting
CRPX0 Ransomware Group

The article analyzes the CRPX0 ransomware program and affiliate panel, including generated payload behavior and the v3.0 feature set.

DataBreachPlus

The ransomware component communicates with three Russian .ru domains and uses the ransomware-as-a-service identity "DataBreachPlus" with Telegram, qTox, and ProtonMail contact channels.

MITRE ATT&CK

crpx0 in ATT&CK

53 distinct techniques

Techniques

53 techniques
T1562.001 Disable or Modify Tools T1053.005 Scheduled Task T1070.004 File Deletion T1497 Virtualization/Sandbox Evasion T1041 Exfiltration Over C2 Channel T1548.002 Bypass User Account Control T1071.001 Web Protocols T1204.002 Malicious File T1486 Data Encrypted for Impact T1115 Clipboard Data T1027 Obfuscated Files or Information T1047 Windows Management Instrumentation T1059.001 PowerShell T1055 Process Injection T1005 Data from Local System T1543.001 Launch Agent T1036 Masquerading T1105 Ingress Tool Transfer T1021.002 SMB/Windows Admin Shares T1490 Inhibit System Recovery T1218.011 Rundll32 T1140 Deobfuscate/Decode Files or Information T1083 File and Directory Discovery T1082 System Information Discovery T1135 Network Share Discovery T1518.001 Security Software Discovery T1491.001 Internal Defacement T1090.003 Multi-hop Proxy T1482 Domain Trust Discovery T1204.001 Malicious Link T1574.001 DLL T1027.006 HTML Smuggling T1555 Credentials from Password Stores T1560 Archive Collected Data T1570 Lateral Tool Transfer T1552.001 Credentials In Files T1021.004 SSH T1189 Drive-by Compromise T1059.004 Unix Shell T1560.001 Archive via Utility T1016 System Network Configuration Discovery T1059.006 Python T1537 Transfer Data to Cloud Account T1204 User Execution T1565.002 Transmitted Data Manipulation T1059.005 Visual Basic T1113 Screen Capture T1102.001 Dead Drop Resolver T1553 Subvert Trust Controls T1027.010 Command Obfuscation T1566 Phishing T1566.002 Spearphishing Link T1539 Steal Web Session Cookie

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.