DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // CRPXOFIRST SEEN: JUL 2026

CRPxO

ALSO KNOWN AS: None confirmed
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Unknown (CIS-region suspected based on CIS-country targeting exclusions)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:JUL 2026
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL39/100
RESOURCES39/100
PERSISTENCE42/100
STEALTH34/100
IMPACT48/100

CRPxO is a newly surfaced ransomware-as-a-service operation, first observed in July 2026, with at least 6 confirmed victims across the US and China within its debut month. The group runs a double-extortion leak site and is actively recruiting affiliates at a 70/30 revenue split with a low $333 buy-in, suggesting rapid scaling intent. A significant OPSEC failure exposed its backend admin and phpMyAdmin database login pages publicly, a hallmark of immature operations — though its v2.0 platform advertises hybrid encryption, multi-stage data theft, and anti-sandbox evasion.

Financial — double extortion via RaaS affiliate model with low entry-cost ($333) recruitment

Double extortion, ClickFix lure delivery (fake CAPTCHA/browser errors), RDP credential compromise, phishing for initial access, hybrid encryption, multi-stage data theft, obfuscated payload delivery, anti-sandbox logic, data published on DLS if unpaid

HEALTHCARE
TECHNOLOGY
PROFESSIONAL SERVICES
FINANCIAL SERVICES
PHARMACEUTICALS

Dark web leak site (DLS with exposed admin/phpMyAdmin panels — OPSEC failure documented); CIS-country geofencing; XMR/BTC cryptocurrency payouts to affiliates

FILE DATE: JUL 2026
Debut Campaign — Multi-Sector Blitz
Within days of appearing on ransomware.live on July 27, 2026, CRPxO listed victims including FLP Law Group (US legal), Prei Capital (US finance), Bright Star Partners Insurance, CodeConductor.ai (US AI/SaaS, 52.4 GB exfiltrated), and AMHWA Biopharm (China pharma, 37 GB threatened for leak).
SHARE BRIEF:✕ Post on Xin Share on LinkedIn