Tags:

CRPX0 — SCAMMER TURNED RANSOMWARE OPERATOR

NOTE: This Research Article focuses on the CRPX0 Ransomware Group, releasing samples (which has not yet been public as of now) and uncovering a Scam Service which was running by the same group, before launching Ransomware Program.

INDEX

INTRODUCTION
DOMAIN ANALYSIS
VICTIM PAGE
SERVICES EXPLAINED IN DLS
YOUTUBE PROMOTION
FLASH TOKEN — MONEY LAUNDERING SCAM
TAILING TELEGRAM CHANNELS
UNCOVERING REAL IP ADDRESSES
BITCOIN ADDRESS
AFFILIATE PANEL
EXECUTION CHAIN/ BEHAVIORAL ANALYSIS
IOCs
MITRE ATT&CK
CONCLUSION

Ready to Setup Service for Criminals | Credit: Cristian Montes | Deviant Art

INTRODUCTION

In early July 2026, a new group emerged named CRPX0 listing about 30+ victims in a month, on Dark Web, targeting mainly the US.

What stands out from the victim list is the count of Victims from Turkey which stands 2nd just after the US, unlike UK or Canada.

DLS of CRPX0 Group

Unlike other Ransomware Groups, they launched their service both on Dark Web and Clear Web by listing 3 domains:-

tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion 
xburs4nr6cbuktokhqwefeh5hsjakz6usll5o7z5uhrfcnolakj4ptad.onion 
crpx0.su

The group does NOT uses Vanity Domain Name as it’s a randomly generated Onion Domain. 

User-Friendly filters are given in the DLS for the visitor to identify the latest victims (with count down timer) and expired ones separately. 

DOMAIN ANALYSIS

During investigation, we found 3 active clear web domains which are associated with CRPX0 Ransomware Group. 

They are:-

DOMAIN : REGISTRATION DATE
==========================
option.spark198.com: 19th April 2021
crpx0.su: 14th June 2026
crpxoxo.pw : 13th July 2026

While checking out the Registration Details of the Clear Web DLS, it is found that the site is registered on 14th June, 2026.

Domain Registry Details #1
CRPX0 Panel Hosted #1

This functioning service is registered at REGRU-SU which is a non-compliant registrar based in Russia. It was being abused by multiple threat actors like INC Ransomware Group (to host their clearweb). 

Exactly, a month later, the group again registered a domain in July 2026

Domain Registry Details #2
CRPX0 Panel Hosted #2

However, the one that stands out which is registered back in 2021. 

Domain Registry Details #2

Hence, it could be assumed that this domain was being repurposed to host CRPX0 Panel as found below:-

CRPx0 Panel: #2

NOTE: It is important to note here that the other 2 domains could be a staging/test server for CRPX0 Project as the real victims are NOT listed. 

So Onion Domain tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion and the crpx0.su is only working (listing real victims) at the moment as DLS both in Dark Web and Clear Web respectively. 

From the registered timeline, we can assume that the Onions also went live during that time-frame [June-July 2026].

VICTIM PAGE

While analyzing the victim data page, it is found that small samples are listed as a proof of Hack in the “Leak Proof Directory”. 

 Victim Page #1
Victim Page #2

Though the listed data is in GBs, the leak proof for the same is in KBs. This implies that the hacked/infiltrated victim data for sale to the intended DarkWeb customers. 

It is also found that there are multiple Session IDs generated for each victim, while keeping the TOX ID as same which is 17EB54B8455144E088C7E77F88A97221C319F0CFE4FE306853EEB113EE8DB5607BB6EE481C7C.

Session IDs

05c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3
05b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2
05f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0
05e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9
05d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8
05c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7
05a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5
05f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4
05d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2
05c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1
05b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0
05a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9
05f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8
05e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7
05d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6
05c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5
05e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1
05f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6
05a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7
05b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8
05c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9
05d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0
05f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2
05a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3
05b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4
050546f6719172e04151c31acb37a242fa3eeff5766aa57331d26cc06e83e9e25b
05df62a71f00cb1017ef0d19bd942cf12674e2d26f07a27ebcd00a297b8764ef1a
05cb6b297ea4f3c7e0988de21b4a1b023e9c8dd41221efc029ba8f52de2b281cfd
05ac11bf7bde8290f6534ef03dcd227d812d4d9b23b12ceecfdd91b8a8b19ee762
05fc9a83b2c1e4f5a6d7e8f90123456789abcdef0123456789abcdef0123456
05da7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6

Among this, 050546f6719172e04151c31acb37a242fa3eeff5766aa57331d26cc06e83e9e25b serves as the primary touch point of Threat Actors for official purposes. But the same has been spotted with 2–3 victim page as well. 

In total, there are 47 Victims listed, where most of the affected sector is Healthcare Industry

SERVICES EXPLAINED IN DLS

Some of the service updates found in their DLS are:-

1. HAAS

HAAS #1

As general rule of Thumb, CIS countries would be excluded from the attack. 

HAAS #2

2. RAAS

The group also offers RAAS Platform, 

RAAS #1
RAAS #2

3. AFFILIATE PROGRAM

The group offers payload of their-own program to the affiliate members 

Affiliate Program #1
Affiliate Program #2

As per the offering found in the Advertisement, the targeted payloads are against Windows Environment offering EXE and DLL files. 

Another interesting caveat is the adoption of ClickFix Delivery which is notable in victimizing internally by the user, without any external factors. 

ClickFix Promotion

NOTE: ClickFix technique can be easily defended by providing Cyber Awareness about Powershell Command Running

4. CRPX0 v2.0 — Now Available

The group had already released 2nd version of their tool without even making any strong presence for the initial version. 

CRPX0 New Build Notification

They also pressurizes/lures the users who are visiting the website for a “Quick-Register” pressure tactic for the amount. 

5. NEWS

In this section, the group lists the security Blog Reports focused on the CRPX0 coverage by various Security Vendors. 

CRPX0 Media Coverage

This trend was spotted in APT73

YOUTUBE PROMOTION

Making a product does not end the work, though the sales and promotion makes it more reachable to the wider audience. Hence, threat actors also created a Video about the Panel on Youtube.

The threat actor had created a Youtube video detailing the walkthrough of CRPx0 Ransomware Affiliate Panel. Upon analyzing the video, it is found that the the voice is NOT AI-Generated and is a legitimate one for the video, signalling a non-native English Speaker. It is far more consistent with a real non-native English speaker doing a live (or semi-live) screen-recording narration of software.

Modern AI voice tools can sound very natural and can even be prompted to include imperfections, but the specific pattern here (consistent article/preposition/subject-verb mistakes mixed with fluent technical vocabulary, plus the real-time “I’m clicking generate… now downloading…” flow) aligns better with a person speaking while operating the demo.

It is notable that the test machine found in the Youtube video is Mandarin, which signals China, though not a strong indicator to point China.

From the video demo, it is evident that there is a new TOR Domain is generated for Negotiation along with a Recovery ID to get in contact with the team like:-

Nego: kqi5yty6ipuhwz4anutty6hob6et7dvnnxg6kcnulwedjaz5oton2zyd.onion
Recovery ID: OP_1782821901

LET’S HUNT THE PAST…

FLASH TOKEN — MONEY LAUNDERING SCAM

In March 2026, the group had started Flash Token Shop at flash-token.shop. 

As per the service, the following is quoted:-

“Experience the industry’s most reliable Flash USDT and Crypto Flash generation service. Our audited smart contracts allow you to buy Flash tokens for testing, demonstrations, and liquidity simulations.”

“Flash tokens are synthetic assets generated via smart contracts that mirror real tokens on the blockchain for a temporary duration. They are used for liquidity testing and contract demonstrations” — As per Threat Actor

Let us uncover the logic behind this Scam Service.

How the Trick Works: Scammers use a modified token contract or an unconfirmed transaction broadcast to display a fake balance in a target wallet. The wallet interface displays the funds visually, but because the transaction lacks a valid network fee or collateral, the blockchain protocol eventually rejects it.

The “Temporary” Illusion: When the network drops the unconfirmed transaction (or when a centralized wallet patches the visual glitch), the balance completely vanishes. The scammers label this automated network rejection as a “temporary duration asset feature” to explain away why the funds disappear.

The group had registered this service on 11th March 2026, 3 months before kick-starting CRPX0 Ransomware Project. 

Here is the Bitcoin Deposit Address of their running service:-

1Fv8YVf52MGqjfgnyjMoBo7ojoGnZmKCrV

BTC Address of Flash Token Service
TOX ID and Telegram Support in Flash Token Service

The registered address of the above service is located at:-

C/O 10 ANSON ROAD #10–11 INTERNATIONAL PLAZA SINGAPORE

It is a popular blacklisted address, which appeared in Offshore Leaks by ICIJ Investigation. 

TAILING TELEGRAM CHANNELS

During investigation, it is found that there are 2 Telegram Channels found by the group.

1. CRPx0 Official

The primary channel for CRPx0 Ransomware Group created on March 8, 2025. But they posted their initial post on June 17th, 2026.

Initial Post of CRPx0 Telegram Channel

However, their pinned message is from July 1, 2026, the same day when the group uploaded their Demo in Youtube. 

Same Date Spotted for Promotion

2. DATABREACHPLUS

From the Flash Token website, we can see the group is running a Telegram Channel named “DataBreachPlus”. While exploring the channel, it is found that the group had created this TG channel on 3rd March 2025.

TG Channel Created

Upon tracing the earliest message, it is found that the group had actively promoted about their Cryptocurrency Mixer on a platform named “COINLITHIC” which is no more active. However, we can uncover a similar name with the current Ransomware Name spotted as “CryptoX”, which is similar to “CRPX0“.

Coinlithic Page

Upon checking the Registration details of Coinlithic, we can trace the group had started this service in June 2025

WHOIS Data: Coinlithic

SELF-XSS SCAM

While diving deep into the Telegram Channel discussion, I came across another scam tactic used by the group titled “NEW NoOnes Wallet Glitch — Secret VIP Deposit Bonus Unlock (Step-by-Step)” with a Paste URL on March 13, 2026.

This is called Self-XSS Scam which is commonly found in various Pastes to infect users (upon running the same as per instruction). 

Paste about Fake Vulnerability

A bunch of Red Flags found here are:-

It asks you to run code, not to just observe a flaw. A real vulnerability report describes a bug; it doesn’t need the “victim” to personally execute a payload in their own browser to “activate” a bonus.

Do not refresh the page” / urgency + time pressure (“30-minute window,” “keep the window open”) is a classic manipulation tactic to stop you from thinking it through or asking someone else.

The payload fetches and eval()s remote code (fetch(...).then(r=>r.text()).then(eval)). This is the actual attack — whatever that hidden URL returns gets executed with full access to your browser session on that site. If you’re logged into your wallet, that code can read your session, trigger withdrawals, steal tokens/cookies, or silently drain funds — all using your own authenticated session, which is exactly why it needs you to paste it yourself (browsers block a real attacker from doing this remotely).

The base64-encoded URL is obfuscation. Legitimate proof-of-concept code doesn’t need to hide the address it’s fetching from.

Double your deposit” bait is the social-engineering hook — too-good-to-be-true financial incentive to short-circuit skepticism.

Like CRPX0, the group had uploaded a demo of the same in Youtube from an account named “VariableX”. 

NOTE: Services like Coinlithic or VariableX (YT Channel) are NOT directly attributed to CRPX0, however Flash Token Service is directly associated with CRPX0 Project due to common TOX ID spotted.

UNCOVERING REAL IP ADDRESSES

While pivoting the ransomware service, found the real IP address which was masked behind Cloudflare:-

https://23.224.4.114
https://23.224.4.115
https://23.224.4.116
https://23.224.4.117
https://23.224.4.118

Here are some of the screenshots:-

CRPx0 Panel: #1

Here is another one:-

CRPx0 Panel: #2

NOTE: Not providing each screenshot as it’s the same for all the listed backend IPs uncovered

Mapping the architecture, we can see that all the services uncovered are hosted with same hosting provider. 

ASN: AS 40065 
ENTITY: CNSERVERS LLC

This ASN is continuously abused by threat actors spreading Cobalt Strike, Supershell etc. Some of the other notable incidents involved are:-

➝CLEO MFT Exploitation: December 2024
➝0-Day CVE-2023–2868 by UNC4841: August 2023
➝Carbine Loader Cryptojacking
➝BadBazaar Espionage: August 2023
➝Ivanti CSA 4.6 Vuln Exploitation: February 2025

BITCOIN ADDRESS

We have seen the deposit address of the group from the services hosted earlier like Flash Token. Tracing that, we can see the following transaction data:

BTC: 1Fv8YVf52MGqjfgnyjMoBo7ojoGnZmKCrV

This is a ByBit Wallet Address which is having an active record of transactions from 12th October 2023 to 8th July 2026 with only few transactions (IN and OUT). 

Here is the quick short snap of BTC Transactions for the above listed wallet:-

Wallet Transaction

The group mainly uses ByBit Hot wallets to keep their money and also depositing large amount to the legacy addresses of ByBit Exchange Wallet Addresses to thwart the investigation. 

  • RED: Main Wallet as Deposit
  • BLACK: Criminal Wallet
  • BLUE: Legacy Wallet

In total, the address has received 0.01655663 BTC ($1036.23) and sent the same amount. 

AFFILIATE PANEL

The affiliate panel runs on xburs4nr6cbuktokhqwefeh5hsjakz6usll5o7z5uhrfcnolakj4ptad.onion which is hosted in a slow network as compared to their DLS. 

CRPX0 Affiliate Panel

It is hosted with Server: nginx/1.28.3 (Ubuntu)

Here by sharing the internal view of the Affiliate Panel of CRPX0 Ransomware Program:-

Dashboard of CRPX0 Group

From the panel, it is found that the group targets Windows and Mac. It is found in the Builder Option. But the Mac is being only targeted via HTML Pages rather than a specialized build. 

4 Options of Build Generation in CRPX0
Panel Settings #1

Here, the Windows ClickFix Stager is having 3 options namely:- DLL Stager, EXE Stager and VBS Stager

ClickFix Stager
Panel Settings #2
Panel Settings #3
Panel Settings #4
Panel Settings #5

Diving deep into the server architecture, following information is uncovered:-

Response Header Analysis

EXECUTION CHAIN/ BEHAVIORAL ANALYSIS

All the generated builds are sized at 3.70MB with default settings (as per the Panel).

Tracing the same naming pattern of EXE files such as: sys_7f6670d8 (sys_ + 8 hex characters + .exe). This is consistent with a dropper / loader family or a distribution site that generates unique filenames for each download.

Let’s check out the Behavior Analysis:-

  1. Delivery — Sample arrives inside an archive; extracted to a user Temp directory (observed as sys_d1c5307f.exe).
  2. Drop & Relaunch — Executable drops a disguised DLL into %LOCALAPPDATA% (sync.dll or index.dll depending on build) and re-executes it as a child process.
  3. Defense Evasion — EDR Unhooking (High severity) — Modifies memory protection on ntdll.dll to PAGE_READWRITE and restores unhooked function bytes, blinding EDR/AV instrumentation to subsequent API calls.
  4. Anti-Analysis Gating — Performs a local time / date-expiration check; samples observed exiting early when run past a built-in expiration window (kill-switch / anti-sandbox behavior).
  5. Second-Stage Staging — Downloads a portable Python 3.10.11 embeddable runtime (python.org, bootstrap.pypa.io, get-pip.py) and extracts it via the legitimate tar.exe (LOLBin technique), avoiding a custom unpacker.
  6. Security Software Takedown — Executes commands (via Python + cmd.exe) to disable multiple antivirus/security services.
  7. Persistence — Creates a scheduled task with the ONLOGON trigger, re-executing the payload at every user logon.
  8. Discovery / Reconnaissance — Performs external/public IP address lookup and network reconnaissance of the host environment.
  9. Network Activity — Outbound HTTP requests to CDN-fronted infrastructure (observed IP ranges consistent with Cloudflare/Fastly), flagged as possible C2/exfiltration; connections were dead/unreachable at analysis time. One incidental request to secure.globalsign.com is assessed as standard Windows CA-chain validation traffic, not actor-controlled.
  10. Anti-Forensics / Cleanup — Deletes the dropped DLL (sync.dll / index.dll) from disk after use.

IOCs

Some of the observed IOCs while analyzing with sandbox environments are:-

URLs (CRPX0 Panel)
==================
https://23.224.4.114
https://23.224.4.115
https://23.224.4.116
https://23.224.4.117
https://23.224.4.118
IP Addresses (Network Fingerprints)
===================================
104.18.21.226
151.101.128.223
146.75.116.175
104.18.20.226
48.192.1.65
151.101.0.223
140.248.136.175
146.75.120.175
146.75.122.133
151.101.192.223
140.248.136.175
FILE PATH
=========
sys_<8-char-hex>.exe (naming pattern)
%LOCALAPPDATA%\sync.dll
%LOCALAPPDATA%\index.dll
%TEMP%\Update_Temp_Store\py.zip
%TEMP%\Update_Temp_Store\python\
IOCs (MD5)
==========
2ff86a4fdfec4a5b49d5545f9a62ec4c
cc2c8ac5aea8d7c36e9161d54e4255f3
4966992c81f7062ed3913ee023240edc
a8e9a638aa9e1c2d73f3432b997d7a7f
ced4c9b53c3c93a4dbefe2f243cd1c71
1ef19373aae940002a980a984f25555b
ea3f9230bb76deb18dedfaea490fd687
DOMAIN
=======
option.spark198.com
crpx0.su
crpxoxo.pw

The malware executed a Python-based payload, performed network reconnaissance, disabled multiple security services, and established persistence through a scheduled task. This behavior indicates a malicious intent to evade detection and maintain access to the system, as per Any Run Analysis.

NOTE: This is a simple analysis for an Executable from CRPX0 Ransomware Project. Rest of the builds are uploaded to VirusTotal and other Platforms as community contribution for deeper analysis.

For Reverse Engineers, here you can find the sample for deeper analysis:-

https://app.any.run/tasks/55a64cc1-3870-4881-abdd-87eb9d1e807e
https://www.virustotal.com/gui/file/28685dff00aa1752b62a8580955b2530d63092bdcc0528b872a668cddad78c11

MITRE ATT&CK

Here is the MITRE ATT&CK parameters for the observed sample:-

MITRE TTPs

CONCLUSION

The group is very interested to keep their presence on surface web which is evident from the Youtube Promotion. 

It is evident that the group now focuses on targeting real victims by offering their service on Dark Web apart from running a Flash Token Scam.

Follow me on Twitter/X for interesting DarkWeb/InfoSec Short findings!

Leave a Reply

Discover more from THE RAVEN FILE

Subscribe now to keep reading and get access to the full archive.

Continue reading