The article analyzes the CRPX0 ransomware program and affiliate panel, including generated payload behavior and the v3.0 feature set.
crpx0
CRPX0 is a financially motivated, cross-platform malware-as-a-service and ransomware-as-a-service operation active since at least 2025–2026.
Profile source: Mallory opens in a new tabcrpx0
Family profile
CRPX0 is a financially motivated, cross-platform malware-as-a-service and ransomware-as-a-service operation active since at least 2025–2026. The CRPX0 brand encompasses a Python-based ransomware component as well as cryptocurrency-focused theft tooling, including clipboard hijacking and BIP39 recovery-phrase discovery. The operation has been associated with the DataBreachPlus identity and an affiliate-oriented commercialization model.
CRPX0 targets Windows, macOS, and Linux systems. Delivery has used ClickFix social-engineering pages masquerading as software-update or CAPTCHA prompts that induce victims to execute clipboard-injected commands. Other observed lure themes include purported shipping documents and adult-content account lists, delivered through archives, malicious shortcuts, and standalone executable or DLL payloads. The staged Windows chain deploys a Python runtime and loader components; macOS delivery similarly deploys portable Python and an obfuscated loader.
The ransomware conducts anti-analysis and defense-evasion activity, including attempts to impair endpoint telemetry, unhook user-mode security instrumentation, terminate security products, and bypass UAC on Windows. It establishes persistence through scheduled tasks on Windows and LaunchAgents on macOS, deletes or degrades local recovery mechanisms, and can self-delete after execution. It performs host, domain, and network-share reconnaissance and supports propagation through remote administration mechanisms, SMB-accessible shares, remote scheduled tasks, WMI, domain policy startup scripts, and SSH-based logic.
Before encryption, CRPX0 collects selected documents and high-value credential material, including password-manager databases, keychain data, private keys, certificates, application secrets, VPN profiles, browser data, authentication tokens, and cryptocurrency recovery phrases. It packages and exfiltrates stolen data to support double extortion. The ransomware encrypts targeted local and reachable network files using per-victim symmetric encryption keys protected with embedded asymmetric cryptography, may use partial encryption for larger files, appends a CRPX0-specific extension, and leaves multilingual ransom notes demanding cryptocurrency payment. Operators threaten publication or sale of stolen data if payment deadlines are not met. Separately, the clipper component monitors and substitutes cryptocurrency wallet addresses in the clipboard, enabling theft of redirected transfers.
Capabilities
- Credential Theft
- Crypto Theft
- Defense Evasion
- Exfiltration
- Initial Access
- Lateral Movement
- Persistence
- Post Exploitation
- Privilege Escalation
- Reconnaissance
- Session Hijacking
Reported operators
Threat actors
2 named in public reportingThe ransomware component communicates with three Russian .ru domains and uses the ransomware-as-a-service identity "DataBreachPlus" with Telegram, qTox, and ProtonMail contact channels.
MITRE ATT&CK