NOTE: This Research Article focuses on the CRPX0 Ransomware Group, releasing samples (which has not yet been public as of now) and uncovering a Scam Service which was running by the same group, before launching Ransomware Program.
INDEX
INTRODUCTION
DOMAIN ANALYSIS
VICTIM PAGE
SERVICES EXPLAINED IN DLS
YOUTUBE PROMOTION
FLASH TOKEN — MONEY LAUNDERING SCAM
TAILING TELEGRAM CHANNELS
UNCOVERING REAL IP ADDRESSES
BITCOIN ADDRESS
AFFILIATE PANEL
EXECUTION CHAIN/ BEHAVIORAL ANALYSIS
IOCs
MITRE ATT&CK
CONCLUSION

INTRODUCTION
In early July 2026, a new group emerged named CRPX0 listing about 30+ victims in a month, on Dark Web, targeting mainly the US.
What stands out from the victim list is the count of Victims from Turkey which stands 2nd just after the US, unlike UK or Canada.

Unlike other Ransomware Groups, they launched their service both on Dark Web and Clear Web by listing 3 domains:-
tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onionxburs4nr6cbuktokhqwefeh5hsjakz6usll5o7z5uhrfcnolakj4ptad.onioncrpx0.su
The group does NOT uses Vanity Domain Name as it’s a randomly generated Onion Domain.
User-Friendly filters are given in the DLS for the visitor to identify the latest victims (with count down timer) and expired ones separately.
DOMAIN ANALYSIS
During investigation, we found 3 active clear web domains which are associated with CRPX0 Ransomware Group.
They are:-
DOMAIN : REGISTRATION DATE==========================option.spark198.com: 19th April 2021crpx0.su: 14th June 2026crpxoxo.pw : 13th July 2026
While checking out the Registration Details of the Clear Web DLS, it is found that the site is registered on 14th June, 2026.


This functioning service is registered at REGRU-SU which is a non-compliant registrar based in Russia. It was being abused by multiple threat actors like INC Ransomware Group (to host their clearweb).
Exactly, a month later, the group again registered a domain in July 2026.


However, the one that stands out which is registered back in 2021.

Hence, it could be assumed that this domain was being repurposed to host CRPX0 Panel as found below:-

NOTE: It is important to note here that the other 2 domains could be a staging/test server for CRPX0 Project as the real victims are NOT listed.
So Onion Domain tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion and the crpx0.su is only working (listing real victims) at the moment as DLS both in Dark Web and Clear Web respectively.
From the registered timeline, we can assume that the Onions also went live during that time-frame [June-July 2026].
VICTIM PAGE
While analyzing the victim data page, it is found that small samples are listed as a proof of Hack in the “Leak Proof Directory”.


Though the listed data is in GBs, the leak proof for the same is in KBs. This implies that the hacked/infiltrated victim data for sale to the intended DarkWeb customers.
It is also found that there are multiple Session IDs generated for each victim, while keeping the TOX ID as same which is 17EB54B8455144E088C7E77F88A97221C319F0CFE4FE306853EEB113EE8DB5607BB6EE481C7C.
Session IDs
05c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c305b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b205f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f005e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e905d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d805c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c705a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a505f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f405d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d205c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c105b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b005a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a905f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f805e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e705d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d605c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c505e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e105f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f605a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a705b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b805c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c905d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d005f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f205a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a305b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4050546f6719172e04151c31acb37a242fa3eeff5766aa57331d26cc06e83e9e25b05df62a71f00cb1017ef0d19bd942cf12674e2d26f07a27ebcd00a297b8764ef1a05cb6b297ea4f3c7e0988de21b4a1b023e9c8dd41221efc029ba8f52de2b281cfd05ac11bf7bde8290f6534ef03dcd227d812d4d9b23b12ceecfdd91b8a8b19ee76205fc9a83b2c1e4f5a6d7e8f90123456789abcdef0123456789abcdef012345605da7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4e5f6
Among this, 050546f6719172e04151c31acb37a242fa3eeff5766aa57331d26cc06e83e9e25b serves as the primary touch point of Threat Actors for official purposes. But the same has been spotted with 2–3 victim page as well.
In total, there are 47 Victims listed, where most of the affected sector is Healthcare Industry
SERVICES EXPLAINED IN DLS
Some of the service updates found in their DLS are:-
1. HAAS

As general rule of Thumb, CIS countries would be excluded from the attack.

2. RAAS
The group also offers RAAS Platform,


3. AFFILIATE PROGRAM
The group offers payload of their-own program to the affiliate members


As per the offering found in the Advertisement, the targeted payloads are against Windows Environment offering EXE and DLL files.
Another interesting caveat is the adoption of ClickFix Delivery which is notable in victimizing internally by the user, without any external factors.

NOTE: ClickFix technique can be easily defended by providing Cyber Awareness about Powershell Command Running
4. CRPX0 v2.0 — Now Available
The group had already released 2nd version of their tool without even making any strong presence for the initial version.

They also pressurizes/lures the users who are visiting the website for a “Quick-Register” pressure tactic for the amount.
5. NEWS
In this section, the group lists the security Blog Reports focused on the CRPX0 coverage by various Security Vendors.

This trend was spotted in APT73
YOUTUBE PROMOTION
Making a product does not end the work, though the sales and promotion makes it more reachable to the wider audience. Hence, threat actors also created a Video about the Panel on Youtube.
The threat actor had created a Youtube video detailing the walkthrough of CRPx0 Ransomware Affiliate Panel. Upon analyzing the video, it is found that the the voice is NOT AI-Generated and is a legitimate one for the video, signalling a non-native English Speaker. It is far more consistent with a real non-native English speaker doing a live (or semi-live) screen-recording narration of software.
Modern AI voice tools can sound very natural and can even be prompted to include imperfections, but the specific pattern here (consistent article/preposition/subject-verb mistakes mixed with fluent technical vocabulary, plus the real-time “I’m clicking generate… now downloading…” flow) aligns better with a person speaking while operating the demo.
It is notable that the test machine found in the Youtube video is Mandarin, which signals China, though not a strong indicator to point China.
From the video demo, it is evident that there is a new TOR Domain is generated for Negotiation along with a Recovery ID to get in contact with the team like:-
Nego: kqi5yty6ipuhwz4anutty6hob6et7dvnnxg6kcnulwedjaz5oton2zyd.onion
Recovery ID: OP_1782821901
LET’S HUNT THE PAST…
FLASH TOKEN — MONEY LAUNDERING SCAM
In March 2026, the group had started Flash Token Shop at flash-token.shop.
As per the service, the following is quoted:-
“Experience the industry’s most reliable Flash USDT and Crypto Flash generation service. Our audited smart contracts allow you to buy Flash tokens for testing, demonstrations, and liquidity simulations.”
“Flash tokens are synthetic assets generated via smart contracts that mirror real tokens on the blockchain for a temporary duration. They are used for liquidity testing and contract demonstrations” — As per Threat Actor
Let us uncover the logic behind this Scam Service.
How the Trick Works: Scammers use a modified token contract or an unconfirmed transaction broadcast to display a fake balance in a target wallet. The wallet interface displays the funds visually, but because the transaction lacks a valid network fee or collateral, the blockchain protocol eventually rejects it.
The “Temporary” Illusion: When the network drops the unconfirmed transaction (or when a centralized wallet patches the visual glitch), the balance completely vanishes. The scammers label this automated network rejection as a “temporary duration asset feature” to explain away why the funds disappear.
The group had registered this service on 11th March 2026, 3 months before kick-starting CRPX0 Ransomware Project.

Here is the Bitcoin Deposit Address of their running service:-
1Fv8YVf52MGqjfgnyjMoBo7ojoGnZmKCrV


The registered address of the above service is located at:-
C/O 10 ANSON ROAD #10–11 INTERNATIONAL PLAZA SINGAPORE
It is a popular blacklisted address, which appeared in Offshore Leaks by ICIJ Investigation.
TAILING TELEGRAM CHANNELS
During investigation, it is found that there are 2 Telegram Channels found by the group.
1. CRPx0 Official
The primary channel for CRPx0 Ransomware Group created on March 8, 2025. But they posted their initial post on June 17th, 2026.

However, their pinned message is from July 1, 2026, the same day when the group uploaded their Demo in Youtube.

2. DATABREACHPLUS
From the Flash Token website, we can see the group is running a Telegram Channel named “DataBreachPlus”. While exploring the channel, it is found that the group had created this TG channel on 3rd March 2025.

Upon tracing the earliest message, it is found that the group had actively promoted about their Cryptocurrency Mixer on a platform named “COINLITHIC” which is no more active. However, we can uncover a similar name with the current Ransomware Name spotted as “CryptoX”, which is similar to “CRPX0“.

Upon checking the Registration details of Coinlithic, we can trace the group had started this service in June 2025.

SELF-XSS SCAM
While diving deep into the Telegram Channel discussion, I came across another scam tactic used by the group titled “NEW NoOnes Wallet Glitch — Secret VIP Deposit Bonus Unlock (Step-by-Step)” with a Paste URL on March 13, 2026.
This is called Self-XSS Scam which is commonly found in various Pastes to infect users (upon running the same as per instruction).

A bunch of Red Flags found here are:-
➝It asks you to run code, not to just observe a flaw. A real vulnerability report describes a bug; it doesn’t need the “victim” to personally execute a payload in their own browser to “activate” a bonus.
➝“Do not refresh the page” / urgency + time pressure (“30-minute window,” “keep the window open”) is a classic manipulation tactic to stop you from thinking it through or asking someone else.
➝The payload fetches and eval()s remote code (fetch(...).then(r=>r.text()).then(eval)). This is the actual attack — whatever that hidden URL returns gets executed with full access to your browser session on that site. If you’re logged into your wallet, that code can read your session, trigger withdrawals, steal tokens/cookies, or silently drain funds — all using your own authenticated session, which is exactly why it needs you to paste it yourself (browsers block a real attacker from doing this remotely).
➝The base64-encoded URL is obfuscation. Legitimate proof-of-concept code doesn’t need to hide the address it’s fetching from.
➝“Double your deposit” bait is the social-engineering hook — too-good-to-be-true financial incentive to short-circuit skepticism.
Like CRPX0, the group had uploaded a demo of the same in Youtube from an account named “VariableX”.
NOTE: Services like Coinlithic or VariableX (YT Channel) are NOT directly attributed to CRPX0, however Flash Token Service is directly associated with CRPX0 Project due to common TOX ID spotted.
UNCOVERING REAL IP ADDRESSES
While pivoting the ransomware service, found the real IP address which was masked behind Cloudflare:-
https://23.224.4.114https://23.224.4.115https://23.224.4.116https://23.224.4.117https://23.224.4.118
Here are some of the screenshots:-

Here is another one:-

NOTE: Not providing each screenshot as it’s the same for all the listed backend IPs uncovered
Mapping the architecture, we can see that all the services uncovered are hosted with same hosting provider.
ASN: AS 40065
ENTITY: CNSERVERS LLC
This ASN is continuously abused by threat actors spreading Cobalt Strike, Supershell etc. Some of the other notable incidents involved are:-
➝CLEO MFT Exploitation: December 2024➝0-Day CVE-2023–2868 by UNC4841: August 2023➝Carbine Loader Cryptojacking➝BadBazaar Espionage: August 2023➝Ivanti CSA 4.6 Vuln Exploitation: February 2025
BITCOIN ADDRESS
We have seen the deposit address of the group from the services hosted earlier like Flash Token. Tracing that, we can see the following transaction data:
BTC: 1Fv8YVf52MGqjfgnyjMoBo7ojoGnZmKCrV
This is a ByBit Wallet Address which is having an active record of transactions from 12th October 2023 to 8th July 2026 with only few transactions (IN and OUT).
Here is the quick short snap of BTC Transactions for the above listed wallet:-

The group mainly uses ByBit Hot wallets to keep their money and also depositing large amount to the legacy addresses of ByBit Exchange Wallet Addresses to thwart the investigation.
- RED: Main Wallet as Deposit
- BLACK: Criminal Wallet
- BLUE: Legacy Wallet
In total, the address has received 0.01655663 BTC ($1036.23) and sent the same amount.
AFFILIATE PANEL
The affiliate panel runs on xburs4nr6cbuktokhqwefeh5hsjakz6usll5o7z5uhrfcnolakj4ptad.onion which is hosted in a slow network as compared to their DLS.

It is hosted with Server: nginx/1.28.3 (Ubuntu)
Here by sharing the internal view of the Affiliate Panel of CRPX0 Ransomware Program:-

From the panel, it is found that the group targets Windows and Mac. It is found in the Builder Option. But the Mac is being only targeted via HTML Pages rather than a specialized build.


Here, the Windows ClickFix Stager is having 3 options namely:- DLL Stager, EXE Stager and VBS Stager.





Diving deep into the server architecture, following information is uncovered:-

EXECUTION CHAIN/ BEHAVIORAL ANALYSIS
All the generated builds are sized at 3.70MB with default settings (as per the Panel).
Tracing the same naming pattern of EXE files such as: sys_7f6670d8 (sys_ + 8 hex characters + .exe). This is consistent with a dropper / loader family or a distribution site that generates unique filenames for each download.
Let’s check out the Behavior Analysis:-
- Delivery — Sample arrives inside an archive; extracted to a user Temp directory (observed as
sys_d1c5307f.exe). - Drop & Relaunch — Executable drops a disguised DLL into
%LOCALAPPDATA%(sync.dllorindex.dlldepending on build) and re-executes it as a child process. - Defense Evasion — EDR Unhooking (High severity) — Modifies memory protection on
ntdll.dlltoPAGE_READWRITEand restores unhooked function bytes, blinding EDR/AV instrumentation to subsequent API calls. - Anti-Analysis Gating — Performs a local time / date-expiration check; samples observed exiting early when run past a built-in expiration window (kill-switch / anti-sandbox behavior).
- Second-Stage Staging — Downloads a portable Python 3.10.11 embeddable runtime (
python.org,bootstrap.pypa.io,get-pip.py) and extracts it via the legitimatetar.exe(LOLBin technique), avoiding a custom unpacker. - Security Software Takedown — Executes commands (via Python +
cmd.exe) to disable multiple antivirus/security services. - Persistence — Creates a scheduled task with the
ONLOGONtrigger, re-executing the payload at every user logon. - Discovery / Reconnaissance — Performs external/public IP address lookup and network reconnaissance of the host environment.
- Network Activity — Outbound HTTP requests to CDN-fronted infrastructure (observed IP ranges consistent with Cloudflare/Fastly), flagged as possible C2/exfiltration; connections were dead/unreachable at analysis time. One incidental request to
secure.globalsign.comis assessed as standard Windows CA-chain validation traffic, not actor-controlled. - Anti-Forensics / Cleanup — Deletes the dropped DLL (
sync.dll/index.dll) from disk after use.
IOCs
Some of the observed IOCs while analyzing with sandbox environments are:-
URLs (CRPX0 Panel)================== https://23.224.4.114https://23.224.4.115https://23.224.4.116https://23.224.4.117https://23.224.4.118IP Addresses (Network Fingerprints)===================================104.18.21.226151.101.128.223146.75.116.175104.18.20.22648.192.1.65151.101.0.223140.248.136.175146.75.120.175146.75.122.133151.101.192.223140.248.136.175FILE PATH=========sys_<8-char-hex>.exe (naming pattern)%LOCALAPPDATA%\sync.dll%LOCALAPPDATA%\index.dll%TEMP%\Update_Temp_Store\py.zip%TEMP%\Update_Temp_Store\python\IOCs (MD5)==========2ff86a4fdfec4a5b49d5545f9a62ec4ccc2c8ac5aea8d7c36e9161d54e4255f34966992c81f7062ed3913ee023240edca8e9a638aa9e1c2d73f3432b997d7a7fced4c9b53c3c93a4dbefe2f243cd1c711ef19373aae940002a980a984f25555bea3f9230bb76deb18dedfaea490fd687DOMAIN=======option.spark198.comcrpx0.sucrpxoxo.pw
The malware executed a Python-based payload, performed network reconnaissance, disabled multiple security services, and established persistence through a scheduled task. This behavior indicates a malicious intent to evade detection and maintain access to the system, as per Any Run Analysis.
NOTE: This is a simple analysis for an Executable from CRPX0 Ransomware Project. Rest of the builds are uploaded to VirusTotal and other Platforms as community contribution for deeper analysis.
For Reverse Engineers, here you can find the sample for deeper analysis:-
https://app.any.run/tasks/55a64cc1-3870-4881-abdd-87eb9d1e807ehttps://www.virustotal.com/gui/file/28685dff00aa1752b62a8580955b2530d63092bdcc0528b872a668cddad78c11
MITRE ATT&CK
Here is the MITRE ATT&CK parameters for the observed sample:-

CONCLUSION
The group is very interested to keep their presence on surface web which is evident from the Youtube Promotion.
It is evident that the group now focuses on targeting real victims by offering their service on Dark Web apart from running a Flash Token Scam.
Follow me on Twitter/X for interesting DarkWeb/InfoSec Short findings!
Leave a Reply