CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CRPx0 hacking service for dummies claims victim count more than quintupled

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5888

As cited

Copy frozen at (site build).

ransomware

CRPx0 hacking service for dummies claims victim count more than quintupled

CRPx0, a cybercrime operation that shifted from scams to ransomware and cryptocurrency theft over summer 2026, reports expanding from fewer than 10 victims in June to 48 listed on its clearnet site by August 27. The group operates a white-label ransomware-as-a-service platform and hacking service with turnkey infrastructure, using ClickFix social engineering lures (fake Windows Update and Google reCAPTCHA) to deliver Python-based ransomware on Windows and macOS that steals files before encryption with AES-128-CBC. Defenders can block most ClickFix attacks at no cost by disabling the Run dialog for standard users, restricting Terminal access on macOS, and monitoring RunMRU registry writes for PowerShell, curl, or base64 strings.

Why it matters: Organizations face a rapidly scaling threat from an accessible, professionally managed ransomware-as-a-service platform designed to lower technical barriers for affiliate attackers; defenders should immediately implement the recommended detection and prevention controls focused on blocking the ClickFix delivery mechanism and detecting pre-encryption data exfiltration.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

CRPx0 hacking service for dummies claims victim count more than quintupled

CRPx0, a cybercrime operation that shifted from scams to ransomware and cryptocurrency theft over summer 2026, reports expanding from fewer than 10 victims in June to 48 listed on its clearnet site by August 27. The group operates a white-label ransomware-as-a-service platform and hacking service with turnkey infrastructure, using ClickFix social engineering lures (fake Windows Update and Google reCAPTCHA) to deliver Python-based ransomware on Windows and macOS that steals files before encryption with AES-128-CBC. Defenders can block most ClickFix attacks at no cost by disabling the Run dialog for standard users, restricting Terminal access on macOS, and monitoring RunMRU registry writes for PowerShell, curl, or base64 strings.

Why it matters: Organizations face a rapidly scaling threat from an accessible, professionally managed ransomware-as-a-service platform designed to lower technical barriers for affiliate attackers; defenders should immediately implement the recommended detection and prevention controls focused on blocking the ClickFix delivery mechanism and detecting pre-encryption data exfiltration.

VendorsMicrosoftAppleGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary