CRPx0 ransomware service says victim list jumped past 48 firms

CRPx0's white-label ransomware service claims 48 victims as ClickFix lures spread to Windows and macOS.

CSBadmin
2 Min Read

The crime group behind CRPx0 says it has grown from a scam service into a ClickFix-delivered ransomware and crypto-theft operation, with 48 organizations now listed on its clear-web leak site, up from fewer than 10 in June.

The operators sell a white-label ransomware-as-a-service platform: they build and configure command-and-control infrastructure, negotiation panels, and malware so affiliates can bring their own brand. A one-time $10,000 fee later became a 70-30 revenue split with a $333 enrollment charge. The gang bars attacks on Commonwealth of Independent States members and prefers Monero payments.

Affiliates customize ClickFix lures: a fake Windows Update page tricks victims into pasting a PowerShell command into the Run dialog, while a fake Google reCAPTCHA and a macOS curl|bash route deliver the payload. All paths lead to a 1,769-line Python ransomware script that exfiltrates high-value files before encrypting them with AES-128-CBC (Fernet), moves laterally via WMI and scheduled tasks, and gives victims 48 hours to pay.

An August 23 update promises a complete, professional offensive control center for managing compromised machines from one web dashboard, with tools for stealing credentials and cryptocurrency wallet recovery phrases.

Ransomware-ISAC researchers advise defenders to remove the Run dialog for standard users, restrict Terminal via MDM, alert on RunMRU writes containing PowerShell, curl, or long base64 strings, hunt for pre-encryption exfiltration, and keep backups unreachable from compromised accounts.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.