logo

From ZIP File to crpx0 Ransomware: Anatomy of a Multi-Stage Attack

ID: 9f8b012d-b3ea-5fd2-b99d-3faef88ab2ee

STIX ID: report--9f8b012d-b3ea-5fd2-b99d-3faef88ab2ee

Feed Name: Aryaka

Threat Score
72/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Aditya K Sood

...
...

Aryaka Threat Research Labs describes a multi-stage campaign where attackers distribute crpx0 ransomware in a ZIP disguised as “free OnlyFans” content; a malicious shortcut triggers a VBScript loader that installs Python, enabling a remote-controlled payload used for clipboard cryptocurrency theft, credential harvesting, data exfiltration, and escalation to ransomware and extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.