CRPx0 Turns a Crypto Scam Into Ransomware

CRPx0 has pivoted from a crypto scam into a white-label ransomware operation, and its leak site now claims 48 organizations hit, up from fewer than 10 in June. Graham Cluley says the group now runs ransomware and cryptocurrency theft as a business that affiliates can use. Its usual entry point is ClickFix deception: victims are shown a fake error, update, or CAPTCHA and are tricked into pasting a command into Windows Run or a Mac terminal. That gives the attacker execution without exploiting a software bug, after which CRPx0 steals wallet data, swaps clipboard addresses, exfiltrates files, and encrypts the system. For organizations with Windows and macOS users, the exposure is social engineering at the endpoint, not a patchable product flaw. If staff handle cryptocurrency, the same intrusion can add wallet theft and clipboard hijacking to the usual ransom demand, so the damage can extend beyond encrypted machines.

Part of the PlainSec briefing for 2026-09-09

Every edition of this story: CRPx0 Turns a Crypto Scam Into Ransomware

Sources