logo

CRPX0 — SCAMMER TURNED RANSOMWARE OPERATOR

ID: 24d6ca03-a8fe-5304-b82e-2ded3dddbc66

STIX ID: report--24d6ca03-a8fe-5304-b82e-2ded3dddbc66

Feed Name: THE RAVEN FILE

Threat Score
75/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: RakeshKrish

...
...

This research article documents the emergence and operations of the CRPX0 ransomware group (active June–July 2026), detailing their dual clear-web and onion leak sites, affiliate/RAAS services, a preceding Flash Token money-laundering scam, victim listings (~47, heavy in healthcare and US/Turkey), associated infrastructure (domains, hosting ASN, Cloudflare unmasked IPs), behavioral malware analysis (dropper, EDR unhooking, Python second-stage, persistence), and IOCs (domains, TOX ID, BTC address, Telegram channels).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.