SUBJECT PROFILE
CRPxO is a newly surfaced ransomware-as-a-service operation, first observed in July 2026, with at least 6 confirmed victims across the US and China within its debut month. The group runs a double-extortion leak site and is actively recruiting affiliates at a 70/30 revenue split with a low $333 buy-in, suggesting rapid scaling intent. A significant OPSEC failure exposed its backend admin and phpMyAdmin database login pages publicly, a hallmark of immature operations — though its v2.0 platform advertises hybrid encryption, multi-stage data theft, and anti-sandbox evasion.
Financial — double extortion via RaaS affiliate model with low entry-cost ($333) recruitment
OPERATIONAL HISTORY
Double extortion, ClickFix lure delivery (fake CAPTCHA/browser errors), RDP credential compromise, phishing for initial access, hybrid encryption, multi-stage data theft, obfuscated payload delivery, anti-sandbox logic, data published on DLS if unpaid
KNOWN INFRASTRUCTURE
Dark web leak site (DLS with exposed admin/phpMyAdmin panels — OPSEC failure documented); CIS-country geofencing; XMR/BTC cryptocurrency payouts to affiliates