What Is CRPx0?
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business.
What Kind of Scam Did They Operate?
In March 2026, before turning to ransomware, the CRPx0 group ran a crypto scam that showed victims a fake balance in their wallet, making it look like money had arrived. But the "funds" simply disappeared a short while later, because they were never real to begin with.
So Now They're Into Ransomware?
That's right. Their ransomware targets Windows and macOS, with Linux support reportedly in development. The aim of the attack is to firstly steal your cryptocurrency, then steal your data, and then encrypt your device.
According to The Register, CRPx0's own leak site claims to have hit 48 organizations, up from less than 10 in June
Do They Do This on Their Own?
I'm afraid not. Like many other ransomware groups, CRPx0 has transformed itself into a white-label ransomware-as-a-service business - meaning other cybercriminals can join as affiliates and take advantage of its expertise and infrastructure.
So How Are Victims Typically Infected?
The most common infections are through ClickFix attacks, where potential victims are shown a fake error message, a bogus update alert, or a CAPTCHA dialog that tricks them into copying-and-pasting a command into the Windows Run dialog or Mac terminal.
In this way the hackers don't have to exploit a software vulnerability, they just need to trick a user into initiating the attack for them.
I Can't Believe People Are Still Falling for These ClickFix Tricks...
Everyone can make a mistake, or be temporarily distracted and find themselves making a poor decision even if they have been warned of threats like this.
And then, as SecurityWeek reported, one malicious campaign arrived as a ZIP file promising free OnlyFans accounts.
Sigh... ok, I can see how some people would fall for that. So tell me what it does once your systems have been hit
Firstly, CRPx0 monitors your computer's clipboard. If anything that looks like a cryptocurrency wallet address is copied into it to send or receive funds, it silently swaps it for an address belonging to the attackers.
Secondly, the attackers exfiltrate a wide range of data including passwords, wallet recovery phrases, documents, and anything else that could be valuable.
Finally, files are encrypted across the network, leaving a ransom note that gives victims 48 hours to pay up before the stolen data is leaked on the dark web. Encrypted files are given the extension ".crpx0"
Do We Know Where CRPx0 Is Based?
Like I said, it operates more like a franchise than a gang. The entire operation (including control panel, malware, and infrastructure) is sold as a point-and-click kit - meaning that you don't need to be a technical wizard to run it. After paying a one-off fee to become an affiliate, attackers are able to keep a tidy proportion of any ransom payments for themselves.
So the person who has hit you with CRPx0 could be anywhere in the world. However, the central CRPx0 operation appears to have links to Russia. This is borne out by one of the group's rules that no organisations based in countries belonging to the Commonwealth of Independent States are targeted.
So.. Other Than Moving My Company to Russia, What Should I Do about This?
Organizations who feel they may be at risk of being hit by the CRPx0 ransomware and its ilk would be wise to follow Fortra's general advice for defending against ransomware attacks, including implementing strong ransomware protection strategies such as multi-factor authentication, running up-to-date security solutions, and keeping software patches up-to-date.
In addition, we recommend that all companies follow best practices for defending against ransomware attacks, which include tips such as:
- Making secure off-site backups.
- Using hard-to-crack, unique passwords to protect sensitive data and accounts.
- Encrypting sensitive data wherever possible.
- Reducing the attack surface by disabling functionality that your company does not need.
- Educating and informing staff about the risks and methods used by cybercriminals to launch attacks and steal data.
And, as we know CRPx0 often takes advantage of ClickFix attacks, consider restricting access to the Windows Run dialog and locking down Terminal access on Macs for non-technical staff.