NOTE : This Research Article focuses on the CRPX0 Ransomware Group, releasing samples (which has not yet been public as of now) and uncovering a Scam Service which was running by the same group, before launching Ransomware Program.
In early July 2026, a new group emerged named CRPX0 listing 30+ victims in a month, on Dark Web, targeting mainly the US .
What stands out from the victim list is the count of Victims from Turkey which stands 2nd just after the US, unlike UK or Canada .
Unlike other Ransomware Groups, they launched their service both on Dark Web and Clear Web by listing 3 domains:-
The group does NOT uses Vanity Domain Name as it’s a randomly generated Onion Domain.
User-Friendly filters are given in the DLS for the visitor to identify the latest victims (with count down timer) and expired ones separately.
During investigation, we found 3 active clear web domains which are associated with CRPX0 Ransomware Group.
While checking out the Registration Details of the Clear Web DLS, it is found that the site is registered on 14th June, 2026 .
This functioning service is registered at REGRU-SU which is a non-compliant registrar based in Russia . It was being abused by multiple threat actors like INC Ransomware Group (to host their clearweb).
Exactly, a month later, the group again registered a domain in July 2026 .
However, the one that stands out which is registered back in 2021.
Hence, it could be assumed that this domain was being repurposed to host CRPX0 Panel as found below:-
NOTE: It is important to note here that the other 2 domains could be a staging/test server for CRPX0 Project as the real victims are NOT listed.
So Onion Domain tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad.onion and the crpx0.su is only working (listing real victims) at the moment as DLS both in Dark Web and Clear Web respectively.
From the registered timeline, we can assume that the Onions also went live during that time-frame [June-July 2026] .
While analyzing the victim data page, it is found that small samples are listed as a proof of Hack in the “ Leak Proof Directory ”.
Though the listed data is in GBs, the leak proof for the same is in KBs. This implies that the hacked/infiltrated victim data for sale to the intended DarkWeb customers.
It is also found that there are multiple Session IDs generated for each victim, while keeping the TOX ID as same which is 17EB54B8455144E088C7E77F88A97221C319F0CFE4FE306853EEB113EE8DB5607BB6EE481C7C .
Among this, 050546f6719172e04151c31acb37a242fa3eeff5766aa57331d26cc06e83e9e25b serves as the primary touch point of Threat Actors for official purposes. But the same has been spotted with 2–3 victim page as well.
In total, there are 47 Victims listed, where most of the affected sector is Healthcare Industry
Some of the service updates found in their DLS are:-
As general rule of Thumb, CIS countries would be excluded from the attack.
The group also offers RAAS Platform,
The group offers payload of their-own program to the affiliate members
Another interesting caveat is the adoption of ClickFix Delivery which is notable in victimizing internally by the user, without any external factors.
NOTE : ClickFix technique can be easily defended by providing Cyber Awareness Powershell Command Running
The group had already released 2nd version of their tool without even making any strong presence for the initial version.
They also pressurizes/lures the users who are visiting the website for a “ Quick-Register ” pressure tactic for the amount.
In this section, the group lists the security Blog Reports focused on the CRPX0 coverage by various Security Vendors.
This trend was spotted in APT73
Making a product does not end the work, though the sales and promotion makes it more reachable to the wider audience. Hence, threat actors also created a Video the Panel on Youtube .
The threat actor had created a Youtube video detailing the walkthrough of CRPx0 Ransomware Affiliate Panel . Upon analyzing the video, it is found that the the voice is NOT AI-Generated and is a legitimate one for the video, signalling a non-native English Speaker. It is far more consistent with a real non-native English speaker doing a live (or semi-live) screen-recording narration of software.
Modern AI voice tools can sound very natural and can even be prompted to include imperfections, but the specific pattern here (consistent article/preposition/subject-verb mistakes mixed with fluent technical vocabulary, plus the real-time “ I’m clicking generate… now downloading… ” flow) aligns better with a person speaking while operating the demo.
It is notable that the test machine found in the Youtube video is Mandarin , which signals China , though not a strong indicator to point China.
From the video demo, it is evident that there is a new TOR Domain is generated for Negotiation along with a Recovery ID to get in with the team like:-
Nego: kqi5yty6ipuhwz4anutty6hob6et7dvnnxg6kcnulwedjaz5oton2zyd.onion Recovery ID: OP_1782821901
In March 2026, the group had started Flash Token Shop at flash-token.shop.
As per the service, the following is quoted:-
“Experience the industry’s most reliable Flash USDT and Crypto Flash generation service. Our audited smart contracts allow you to buy Flash tokens for testing, demonstrations, and liquidity simulations.”
“Flash tokens are synthetic assets generated via smart contracts that mirror real tokens on the blockchain for a temporary duration. They are used for liquidity testing and contract demonstrations” — As per Threat Actor
Let us uncover the logic behind this Scam Service.
How the Trick Works : Scammers use a modified token contract or an unconfirmed transaction broadcast to display a fake balance in a target wallet. The wallet interface displays the funds visually, but because the transaction lacks a valid network fee or collateral, the blockchain protocol eventually rejects it.
The “Temporary” Illusion : When the network drops the unconfirmed transaction (or when a centralized wallet patches the visual glitch), the balance completely vanishes. The scammers label this automated network rejection as a “temporary duration asset feature” to explain away why the funds disappear.
The group had registered this service on 11th March 2026 , 3 months before kick-starting CRPX0 Ransomware Project.
Here is the Bitcoin Deposit Address of their running service:-
1Fv8YVf52MGqjfgnyjMoBo7ojoGnZmKCrV
The registered address of the above service is located at:-
C/O 10 ANSON ROAD #10–11 INTERNATIONAL PLAZA SINGAPORE
It is a popular blacklisted address, which appeared in Offshore Leaks by ICIJ Investigation.
During investigation, it is found that there are 2 Telegram Channels found by the group.
The primary channel for CRPx0 Ransomware Group created on March 8, 2025 . But they posted their initial post on June 17th, 2026 .
However, their pinned message is from July 1, 2026, the same day when the group uploaded their Demo in Youtube.
From the Flash Token website, we can see the group is running a Telegram Channel named “ DataBreachPlus ”. While exploring the channel, it is found that the group had created this TG channel on 3rd March 2025 .
Upon tracing the earliest message, it is found that the group had actively their Cryptocurrency Mixer on a platform named “ COINLITHIC ” which is no more active. However, we can uncover a similar name with the current Ransomware Name spotted as “ CryptoX ”, which is similar to “ CRPX0 “.
Upon checking the Registration details of Coinlithic, we can trace the group had started this service in June 2025 .
While diving deep into the Telegram Channel discussion, I came across another scam tactic used by the group titled “ NEW NoOnes Wallet Glitch — Secret VIP Deposit Bonus Unlock (Step-by-Step) ” with a Paste URL on March 13, 2026.
This is called Self-XSS Scam which is commonly found in various Pastes to infect users (upon running the same as per instruction).
A bunch of Red Flags found here are:-
➝ It asks you to run code, not to just observe a flaw . A real vulnerability report describes a bug; it doesn’t need the “victim” to personally execute a payload in their own browser to “activate” a bonus.
➝ “ Do not refresh the page” / urgency + time pressure (“30-minute window,” “keep the window open”) is a classic manipulation tactic to stop you from thinking it through or asking someone else.
➝ The payload fetches and eval() s remote code ( fetch(...).then(r=>r.text()).then(eval) ). This is the actual attack — whatever that hidden URL returns gets executed with full access to your browser session on that site. If you’re logged into your wallet, that code can read your session, trigger withdrawals, steal tokens/cookies, or silently drain funds — all using your own authenticated session, which is exactly why it needs you to paste it yourself (browsers block a real attacker from doing this remotely).
➝ The base64-encoded URL is obfuscation . Legitimate proof-of-concept code doesn’t need to hide the address it’s fetching from.
➝ “ Double your deposit ” bait is the social-engineering hook — too-good-to-be-true financial incentive to short-circuit skepticism.
Like CRPX0, the group had uploaded a demo of the same in Youtube from an account named “ VariableX ”.
NOTE: Services like Coinlithic or VariableX (YT Channel) are NOT directly attributed to CRPX0, however Flash Token Service is directly associated with CRPX0 Project due to common TOX ID spotted.
While pivoting the ransomware service, found the real IP address which was masked behind Cloudflare:-
Here are some of the screenshots:-
Here is another one:-
NOTE : Not providing each screenshot as it’s the same for all the listed backend IPs uncovered
Mapping the architecture, we can see that all the services uncovered are hosted with same hosting provider.
ASN: AS 40065 ENTITY: CNSERVERS LLC
This ASN is continuously abused by threat actors spreading Cobalt Strike , Supershell etc. Some of the other notable incidents involved are:-
We have seen the deposit address of the group from the services hosted earlier like Flash Token. Tracing that, we can see the following transaction data:
This is a ByBit Wallet Address which is having an active record of transactions from 12th October 2023 to 8th July 2026 with only few transactions (IN and OUT).
Here is the quick short snap of BTC Transactions for the above listed wallet:-
The group mainly uses ByBit Hot wallets to keep their money and also depositing large amount to the legacy addresses of ByBit Exchange Wallet Addresses to thwart the investigation.
In total, the address has received 0.01655663 BTC ($1036.23) and sent the same amount.
The affiliate panel runs on xburs4nr6cbuktokhqwefeh5hsjakz6usll5o7z5uhrfcnolakj4ptad.onion which is hosted in a slow network as compared to their DLS.
It is hosted with Server: nginx/1.28.3 (Ubuntu)
Here by sharing the internal view of the Affiliate Panel of CRPX0 Ransomware Program:-
From the panel, it is found that the group targets Windows and Mac . It is found in the Builder Option. But the Mac is being only targeted via HTML Pages rather than a specialized build.
Here, the Windows ClickFix Stager is having 3 options namely:- DLL Stager , EXE Stager and VBS Stager .
Diving deep into the server architecture, following information is uncovered:-
All the generated builds are sized at 3.70MB with default settings (as per the Panel).
Tracing the same naming pattern of EXE files such as: sys_7f6670d8 (sys_ + 8 hex characters + .exe). This is consistent with a dropper / loader family or a distribution site that generates unique filenames for each download.
Let’s check out the Behavior Analysis:-
On August 18, the group had made a 5 minute promotional podcast on Spotify platform.
On the same day, they uploaded a working video of EDR Killer which defends the current security gateways, sold for $550.
Here is the video of the same:-
NOTE : The working video is not a direct proof and could be used in a controlled environment to make the visitors believe the genuineness of the tool they advertise.
On August 23, the group had announced the Version 3 of CRPX0 Ransomware Program on their Telegram Channel with their description on their website.
As per the post, here is the content which can be found at:-
From the post, it is found that there are few add-ons offered like Clipper services introduced into the program.
NOTE : When you see quicker versions of Ransomware builds are being at an aggressive level within a limited time frame, the chances of turning it into a Scam is higher.
The newly added victims are genuine like before and they hold data for real.
FOLLOW THIS ARTICLE FOR FREQUENT UPDATE !
Some of the observed IOCs while analyzing with sandbox environments are:-
The malware executed a Python-based payload, performed network reconnaissance, disabled multiple security services, and established persistence through a scheduled task. This behavior indicates a malicious intent to evade detection and maintain access to the system, as per Any Run Analysis .
NOTE : This is a simple analysis for an Executable from CRPX0 Ransomware Project. Rest of the builds are uploaded to VirusTotal and other Platforms as community contribution for deeper analysis.
For Reverse Engineers, here you can find the sample for deeper analysis:-
Here is the MITRE ATT&CK parameters for the observed sample:-
The group is very interested to keep their presence on surface web which is evident from the Youtube Promotion.
It is evident that the group now focuses on targeting real victims by offering their service on Dark Web apart from running a Flash Token Scam.
Though the group “claims” to hold large data breaches (we never know), they didn’t leak the databases like other Ransomware Groups (As of now) do. This could also signal the possibility of either partial attack or the chance of Data Sale on Dark Web/Telegram Channels.
Follow me on Twitter/X for interesting DarkWeb/InfoSec Short findings!
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
