Skip to content

crpx0

CRPX0 is a multi-stage, financially motivated malware suite and ransomware operation targeting Windows and macOS, with multiple reports indicating cross-platform ransomware support for Linux as well.

Profile source: Mallory opens in a new tab

crpx0

Family profile

CRPX0 is a multi-stage, financially motivated malware suite and ransomware operation targeting Windows and macOS, with multiple reports indicating cross-platform ransomware support for Linux as well. The operation combines several monetization functions: a cryptocurrency clipboard hijacker/clipper, a BIP39 seed phrase scanner and stealer, broader credential and data theft, and a ransomware module used for double extortion. Delivery has been observed through social-engineering lures such as fake OnlyFans account archives and fake FedEx shipping documents. In reported infection chains, victims download a malicious ZIP archive containing a disguised shortcut that executes hidden commands, followed by a VBScript loader and Python-based payloads that connect to a remote server for interactive control, updates, and deployment of additional components.

The crypto theft components monitor clipboard contents for wallet addresses and recovery phrases, replacing copied wallet addresses with attacker-controlled addresses and exfiltrating discovered seed phrases. Reported supported cryptocurrencies include Bitcoin, Ethereum, Tron, Dogecoin, Litecoin, Solana, XRP/Ripple, and Bitcoin Cash, with support for multiple Bitcoin address formats. The seed-finder component scans victim files for 12-word and 24-word BIP39 recovery phrases and exfiltrates matches to the command infrastructure. Reporting also ties the broader operation to infostealer functionality including theft of browser cookies, Discord tokens, Telegram sessions, Steam and Minecraft credentials, 2FA backup codes, screenshots, and other harvested data.

The ransomware component, identified as crypter.py, uses Python Fernet-based encryption, appends the .crpx0 extension to encrypted files, drops ransom notes named HOW TO RECOVER.txt in English, Russian, and Chinese, and changes the victim wallpaper after encryption. It is reported to delete recovery artifacts including Windows shadow copies and macOS/Linux snapshots using utilities such as vssadmin, wmic, wbadmin, tmutil, and timeshift. The campaign has been described as using data exfiltration before or during encryption, targeting documents, media, emails, code, and other sensitive files to support extortion.

The operation is associated with the ransomware-as-a-service identity DataBreachPlus and exposed infrastructure including fanonlyatn[.]xyz as a primary panel/C2 domain, with backup ransomware notification domains caribb[.]ru, mekhovaya-shuba[.]ru, and beboss34[.]ru resolving to 31.31.198[.]206 on REG.RU infrastructure. Reported operator contact channels include Telegram handle @DataBreachPlus, ProtonMail address databreachplus@proton[.]me, and qTox ID 17EB54B8455144E088C7E77F88A97221C319F0CFE4FE306853EEB113EE8DB5607BB6EE481C7C. Additional reported indicators and artifacts include the hardcoded dashboard API secret 26i$MyYe@r, the loader/access password pass2021#, persistence via macOS LaunchAgents such as ~/Library/LaunchAgents/com.sys32.data.plist and com.cryptoprice.guard.plist, Windows persistence via the HKCU Run key CryptoGuard and scheduled task CryptoUpdate, and working directories such as ~/.sys32data and %APPDATA%\sys32data. Reporting assesses the actor as likely Russian-speaking and financially motivated, operating CRPX0 as a MaaS/RaaS-style platform.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 14, 2026
Last activity
Aug 14, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • US1

Leading providers

  • HIVELOCITY, Inc.1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Reported operators

Threat actors

1 named in public reporting
DataBreachPlus

The ransomware component communicates with three Russian .ru domains and uses the ransomware-as-a-service identity "DataBreachPlus" with Telegram, qTox, and ProtonMail contact channels.

MITRE ATT&CK

crpx0 in ATT&CK

25 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.