CRPx0 claims 48 victims amid expanding ransomware service
CRPx0, a cybercrime group that has developed from a scam operation into a ransomware and cryptocurrency-theft service, claims its listed victims rose from fewer than 10 in June to 48 organisations by late August. The claim cannot be independently trusted, but researchers say the group’s growing activity, cross-platform malware and white-label service could make sophisticated attacks easier for less technical criminals to launch.
The group sells services ranging from database theft and network compromise to a ransomware-as-a-service platform, initially priced at $10,000 and later changed to a 70/30 affiliate revenue split after a $333 joining fee. Its ClickFix lures impersonate Windows updates or Google reCAPTCHA prompts to trick victims into running commands, ultimately deploying Python ransomware on Windows or macOS that steals files, encrypts them and sets a 48-hour payment deadline. CRPx0 reportedly avoids targets in CIS countries, prefers Monero payments, and has advertised an updated web dashboard for managing compromised machines.
- CRPx0 claims its victim count has risen sharply since June.
- Its service lets affiliates run branded ransomware campaigns.
- ClickFix lures target both Windows and macOS users.
Read the full article at the source →
Originally published by The Register as “CRPx0 hacking service for dummies claims victim count more than quintupled”.