CRPxO Ransomware Surges to 26 Victims in July With Healthcare-Focused Campaign; 5 New Postings Appear July 27
Emerging RaaS group CRPxO posted five new victims on July 27, 2026 — including American Hospice & Home Health Services (11.3 GB), eCare Platform (14.2 GB), and Bright Star Partners Insurance (41.8 GB) — bringing its total July victim count to 26, predominantly U.S. healthcare organizations. The group geofences CIS-region targets and its v2.0 toolkit incorporates ClickFix social engineering and DLL sideloading, though researchers have also identified exposed backend admin pages indicating poor operational security. CRPxO is actively recruiting affiliates at a 70% revenue share, signaling intent to scale rapidly.
The group geofences CIS-region targets and its v2.0 toolkit incorporates ClickFix social engineering and DLL sideloading, though researchers have also identified exposed backend admin pages indicating poor operational security.
This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the critical severity rating as a guide to prioritization within their environment.
For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.