CRPx0 hacking service for dummies claims victim count more than quintupled
ID: 36f5dd9d-a185-5e31-9f72-0e53c11c7cfa
STIX ID: report--36f5dd9d-a185-5e31-9f72-0e53c11c7cfa
Feed Name: The Register (Security)
CRPx0 is a rapidly evolving cybercrime group offering a white‑label ransomware-as-a-service and crypto‑theft platform called ClickFix that uses social-engineering lures and a portable Python-based payload to exfiltrate data and encrypt victims on Windows and macOS; the service includes a web-based offensive control panel, affiliate revenue sharing, and rules to avoid CIS countries. Researchers detail delivery methods (PowerShell Run dialog and curl|bash), lateral movement techniques (WMI/schtasks), pre-encryption data theft, and detection/mitigation guidance such as disabling Run for standard users, alerting on RunMRU entries, hunting for pre-encryption exfiltration, and ensuring backup isolation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
