Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Technology

CRPx0 ransomware group says victim count surged to 48 organizations

The CRPx0 cybercrime crew reports that its victim list has risen to 48 targets, up from fewer than ten in June, as it expands its ransomware and hacking offerings.

CRPx0, a criminal outfit that transformed from a simple scam service into a ClickFix-delivered ransomware and cryptocurrency theft operation, reports that its victim tally has climbed from under ten in June to 48 organizations, as listed on its clear-web leak page. The group advertises a comprehensive hacking service that includes database extraction, full network compromise, and optional public leak coordination, as well as a white-label ransomware-as-a-service platform that originally required a $10,000 one-time fee.

Profit sharing has shifted from a 100 % affiliate cut to a 70-30 split after a $333 enrollment charge, with a rule prohibiting attacks on Commonwealth of Independent States entities. Its ClickFix payload can be delivered via fake Windows Update or fake Google reCAPTCHA lures, targeting both Windows and macOS, and employs a 1,769-line Python script that encrypts files with AES-128-one outlet after exfiltration. An update on August 23 introduced a v3.0 control panel designed for non-technical operators. Security analysts advise disabling the Run dialog, restricting macOS Terminal, monitoring RunMRU entries, and isolating backups to mitigate the threat.

Why it matters

Expanding ransomware services like CRPx0 raise the danger of large-scale data theft and extortion for enterprises.

In this story

CRPx0ransomwareClickFixhacking servicewhite-label ransomware-as-a-serviceMoneroWindows Update luremacOS curl bash lurethreat intel
Get the beta ↗