In this article

CRPx0 - Threat Actor Profile

CRPx0 is a rapidly expanding ransomware operation combining data theft, cryptocurrency theft, file encryption, and RaaS, with KELA linking the operation to the cybercriminal persona “MrAnon00”.

a black and red logo with the word ikela
By KELA Cyber Intelligence Center
a man in a suit and tie looking at the camera
Fact-check by Lewis Henderson, Director, Intelligence Communications

Updated August 26, 2026

CRPx0 ransomware operation and affiliate service overview

CRPx0 is a technically credible and rapidly expanding ransomware operation combining data theft, cryptocurrency theft, and file encryption, while increasingly offering RaaS, HaaS, and affiliate services. Although its malware, infrastructure, and leak site are genuine, the credibility of its claimed victims remains moderate due to suspiciously rapid growth and limited evidence supporting some disclosures. KELA’s investigation links the operation to the cybercriminal persona “MrAnon00” and the Telegram identity behind DataBreachPlus, revealing a broader history of cryptocurrency scams, malware distribution, and stolen-account activity.

Further OSINT pivots identified a network of aliases, domains, Telegram channels, and business profiles that appear to converge on the threat actor, a Tunisian individual reportedly residing in Volgograd, Russia, providing a strong potential attribution for the CRPx0 operation.

» Get  started for free with KELA  and strengthen your cybersecurity

Background and Activity

CRPx0 is an emerging financially motivated cybercrime operation that combines ransomware with information theft and cryptocurrency theft.

Its malware has reportedly been active since at least July 2025, with capabilities including:

  • Clipboard hijacking to redirect cryptocurrency payments
  • Theft of wallet seed phrases
  • Exfiltration of documents and credentials
  • File encryption using the .CRPx0 extension

The campaign has used social-engineering lures, including fake OnlyFans lures and shipping documents, to persuade victims to open malicious ZIP files or execute disguised commands.

Its ransomware activity was publicly identified in June 2026, when it claimed fewer than ten victims, mainly small healthcare and dental organizations. The operation expanded rapidly in July 2026. CRPx0 appears to be developing a ransomware-as-a-service or white-label model, allowing affiliates or other criminals to use its tools and infrastructure. 

» Here's everything you should know about credential compromise

The Ransom Blog

The CRPx0 website functions as both a ransomware data leak site and a platform for promoting the group's ransomware services. The DLS provides a user-friendly victim directory with filters separating the latest and expired victims, including countdown timers for upcoming disclosures. Individual victim pages contain a "Leak Proof Directory" with small samples of allegedly stolen data, serving as evidence of compromise while the larger datasets are apparently intended for sale to interested parties.

Beyond the leak site, CRPx0 advertises several services, including:

  • HaaS (Hacking as a service)
  • RaaS (Ransomware as a service)
  • An affiliate program, through which affiliates are offered the group's own Windows based EXE and DLL payloads

The platform also promotes ClickFix as a delivery method and advertises the availability of CRPx0 v2.0, despite the group's relatively recent emergence. The website further uses a "Quick Register" mechanism to encourage prospective users to register for the service and includes a dedicated News section featuring security reports and coverage related to CRPX0. The group also promotes its affiliate platform through a YouTube video demonstrating the ransomware panel, including the generation of dedicated Tor negotiation addresses and recovery IDs that can be used to communicate with the CRPx0 operators.

The CRPx0 affiliate panel is hosted on a separate Tor onion address, xburs4nr6cbuktokhqwefeh5hsjakz6usll5o7z5uhrfcnolakj4ptad.onion, and appears to operate on a slower network than the group's DLS. The panel is hosted on Ubuntu and provides affiliates with a builder for generating payloads. The platform supports Windows and Mac, although Mac infections are delivered through HTML pages rather than a dedicated macOS build.

For Windows, the panel provides a ClickFix stager with three available formats:

  1. DLL
  2. EXE
  3. VBS

The affiliate panel therefore appears to provide affiliates with multiple payload generation options and a centralized interface for configuring and deploying CRPX0's infection mechanisms.

CRPx0
Dashboard view of the CRPx0 data leak blog
CRPx0
The "Hacking as a Service" portal page for CRPx0 highlighting targeted operations

» Read more: Ransomware groups are selling network access directly

The Malware

The CRPx0 campaign begins with a malicious zip, shared by the actor as differing offerings like crypto stealer, OnlyFans stealer, Crypto miner, and more. The file disguised an LNK shortcut launching obfuscated commands to download launcher.vbs from fanonlyatn[.]xyz. While displaying a fake credentials file, the loader silently installs Python and executes call2.py, which retrieves further payloads, including sys32.py and the seed-phrase scanner finder.py, establishes persistence on Windows or macOS, profiles the host, and communicates over HTTPS with its C2 infrastructure. 

The malware sends authenticated heartbeats and victim metadata, receives remote tasks and updates, and supports a kill switch through databreach[.]space.

Its capabilities include:

  • Cryptocurrency clipboard hijacking
  • Wallet seed-phrase harvesting
  • Data exfiltration
  • Additional payload execution

When it receives an encryption command, it downloads and runs crypter.py, inventories and encrypts targeted files with the .CRPx0 extension, and sends host data, scan results, and the Fernet encryption key to /CRPx0/notify.php endpoints hosted on caribb[.]ru, mekhovaya-shuba[.]ru, and beboss34[.]ru. The resulting wallpaper and multilingual “CRPx0 hit you” ransom note strongly connect the theft and ransomware components to a single modular operation.

Credibility Assessment

The CRPx0 ransomware operation appears technically credible, with researchers identifying:

  • Real malware
  • C2 infrastructure
  • Source code
  • Cryptocurrency wallets
  • Functioning multi-stage infection chain targeting Windows and macOS

The malware supports cryptocurrency theft, large-scale data exfiltration, and ransomware encryption using the .CRPx0 extension, indicating that CRPx0 is not simply a fabricated ransomware brand or fake leak site.

However, the credibility of its victim claims is less certain. Reported victims increased from fewer than 10 in June 2026 to 47 in July, alongside near synchronous ransom countdowns and limited data disclosures. This raises the possibility of inflated victim numbers or datasets obtained from other breaches. In addition, the fact that the threat actor behind has been involved in multiple scams in the past, is adding to the skepticism surrounding this ransomware group.

Overall, CRPx0 should be considered a genuine and moderate credibility, but potentially opportunistic operation, with its public victim claims requiring independent verification.

Victimology

As of August 2026, CRPx0 has claimed 47 victims across four countries, primarily in:

  • The US: 35 victims (74%)
  • Turkey: 10 victims (21%)

The victimology shows two patterns:

  • High-volume targeting of small and mid-sized US organizations, particularly dental and healthcare practices
  • A coordinated August 1 batch of prominent Turkish targets, including three banks, Turkish Airlines, Aselsan, and Dogan Holding

Across 18 sectors, Healthcare & Life Sciences leads with 11 victims (23%), followed by:

  • Financial Services: 5 victims
  • Technology: 4 victims
  • Manufacturing: 4 victims

This mix of opportunistic targeting and high-profile victims may indicate affiliate-driven operations alongside efforts to build credibility through recognizable targets.

high-profile victims
Chart displaying the distribution of CRPx0 victims by country
high-profile victims
Chart illustrating CRPx0 victims by industry sector, led by Healthcare & Life Sciences

» Make sure you understand the most targeted entry points by attackers

Possible Identification

Forum Activity

The ransom blog has listed multiple Tox and Session identifiers. While the Session ID changed between victims, the Tox ID remained consistent. Searching the Tox ID on KELA’s platform revealed a user named “MrAnon00” and “comebackagain on Altenens Forum using the exact same Tox ID. MrAnon00 maintained a consistent presence on the Altenens forum, primarily engaging in discussions related to cryptocurrency schemes, financial tools, leaked credentials, and compromised subscription accounts. The actor initially participated in discussions involving cryptocurrency wallets and “Flash USDT”, before shifting toward the sharing and promotion of leaked accounts and credentials, including OnlyFans and Instagram account databases. 

MrAnon00 also engaged with threads offering Pornhub Premium and other fresh subscription accounts, “bump” on threads and maintain their visibility. As mentioned previously, a significant portion of the actor’s offerings on the forum appear to be scams and ZIP file lures designed to deliver malware, likely to support his ransomware operations.

MrAnon00
Threat Actors’s post on Altenen Forum, confirming his attribution to CRPx0

The Telegram Leads

The actor’s Telegram channel of the ransomware operation, @CRPX0, was created in March 2025 and currently has approximately 330 subscribers.

Some posts appear to have been deleted, as the next available post is listed as message ID 54. Archived data reveals that the channel was previously named “Cryptoprice.pw,” likely corresponding to a service advertised by the actor.

The channel name was changed in June 2026, after which it began:

  • Advertising victims listed on the ransom blog
  • Sharing a demonstration video showcasing the complete CRPx0 ransomware operation
  • Promoting RaaS offerings
  • Sharing news related to the leaked data

The Telegram user associated with @DataBreachPlus was listed as the contact.

CRPx0 Telegram channel profile
CRPx0 Telegram channel profile

KELA’s investigation of this Telegram user, ID 5604112668, identified the following historical usernames:

  • “DataBreachPlus”
  • “coinlithic”
  • “Mr_Stalingrad”
  • “cryptostealerseller1”
  • “cryptostealerseller”
  • “x0x00xx0x”
  • “the_batman_96”
  • “TheSwapp3rSuppx”
  • “TheSwapp3rSupport”
  • “andrew_687”

The user also listed the domain databreach.space on his Telegram profile.

Based on archived data, this domain appears to have been an earlier version of the actor’s ransomware blog, as archived screenshots show what appear to be victim listings from February 2026.

KELA was also able to identify additional Telegram channels managed by the threat actor, likely supporting his ongoing fraud operations and attempts to infect victims with malware. These channels included:

  • Xray Crypto Miner (@XrayMiner): Used to promote a fake cryptocurrency miner.
  • Flash Token Shop: Also mentioned by him on the forum and used to advertise a cryptocurrency scam (@DataBreachPlusChannel).
  • CryptoStealer (@cryptostealerseller): Used to promote fake crypto-stealer software.

Three additional channels — TrustwalletNightmare, XrayCracker, and CopyGhost — were identified but were inactive. The latter two were also mentioned by the actor on Altenens Forum. The XrayCracker channel was additionally referenced on the Nairaland forum by a user named “alino95”.

Overall, the activity observed across these channels was related to cryptocurrency fraud, fake services, and malware-related schemes.
CryptoStealer
The CryptoSealer Telegram channel, sharing CRPx0 posts
Flash token scam
The actor’s post on his Flash token scam channel
Threat Acto post on Nairaland forum
Threat Actor post on Nairaland forum

» Discover how Telegram’s new data sharing rules affect cybercriminals

Social Media Presence

Searching for the DataBreachPlus Telegram username produced additional results, including a YouTube channel associated with a service called VariableX. The channel contained four videos promoting hacking and fraud related materials that had also been discussed by the actor on Telegram and the forum, including Trust Wallet methods, a crypto wallet generator, and other related content. The YouTube channel also listed the website variablex.ru, which is currently inactive. However, archived data indicates that the website was operating from Volgograd, Russia. The actor has shared multiple websites for his services, while the most are currently inactive: flash-token[.]shop, coinlithic[.]com (just like one of his former Telegram username), and more. The vast majority of the websites identified in connection with the actor were registered through the Russian hosting provider reg.ru.

The VariableX YouTube channel
 Flash token videos
The VariableX YouTube channel, featuring the Flash token videos and the @DataBreachPlus user

On the CryptoStealer and Xray Miner Telegram channels, the actor also promoted an AML Crypto Wallet Checker. OSINT research into the service identified a listing on Product Hunt, where the associated company was listed as “Bot99 Software, Co”. 

In one of the actor’s forum posts, he shared a BTC-to-ETH profit-making method, accompanied by a Google Drive link containing a guide. The same guide was also shared in one of the Telegram channels mentioned above and maintained by the actor.

Using OSINT tools, KELA was able to retrieve the email address associated with the Google Drive file: bot99co@gmail.com .
posts made by the actor
One of the posts made by the actor with the Google Drive link

» Strengthen your cybersecurity with KELA's expertise

The Bot99 Company

OSINT research on this email address and the associated company revealed several leads. The last two digits of the attached phone number were 66, while additional findings included an empty GitHub profile and a Quora profile, created in 2022, listing French and Arabic as the user's primary languages.

Furthermore, company registration details indicate a Tunisian origin and provide a Tunisian phone number, ending in 66 like the one attached to the email address, as well as the company's website, bot99.co. Searching for the website on KELA's platform identified a Nulled forum user from 2020 who was looking to purchase a "dating script" and provided the email addresshello@Bot99.co for contact. Interestingly, the user used the username alino95x, which is almost identical to the username previously identified on the Nairaland forum, alino95.

The Bot99 company details
The Bot99 company details
Threat Actor post on Nulled forum
Threat Actor post on Nulled forum

Multiple searches for the company details identified a person, who was promoting the company on Medium. The same Tunisian phone number was also associated with the threat actor. WHOIS records for bot99.co revealed matching registration details under the name the threat actor, providing an additional email address for pivoting.

Medium Post
Medium post made by likely the owner of Bot99
Old WHOIS Details for the Bot99 website
Old WHOIS Details for the Bot99 website

Who is the threat actor?

OSINT records associated with the email address revealed data leaks and profiles using the usernames "alino1920" and "alino95", as well as a Flickr account associated with Bot99. Additionally, registrations were identified across several cybercrime related forums, including Cardmafia, EliteCarders, and others. The email address also appears to be associated with the registration of 15 domains, including socialposter.org, which was previously mentioned by the Nairaland account.

Multiple registrations under the  threat actor were identified, indicating that he has registered numerous websites, consistent with the threat actor's observed activity. This led to the identification of additional identifiers in WHOIS records, including a new email address, and Russian phone numbers. The domain associated with the new email address led to a personal website that is now inactive. Further pivoting identified a GitHub account where the individual refers to himself that includes a reference to ‘Batman’. The ‘Batman’ alias was also observed among his former Telegram usernames.

Based on Russian leaked records, the threat actor’s Telegram usernames also had a corresponding birth year). Additional social media profiles linked to this identity include Facebook, Instagram, and YouTube. Further analysis of the Russian phone number identified the Telegram account @yournextgov (ID 1924340259). The account was found to be subscribed to various Russian language groups and had also posted comments in multiple groups associated with CRPx0 related activity, including CryptoStealer, TrustWallet, TheSwapp3r, within the very first positive comments after creation. 

Taken together, these identifiers strongly support the assessment that the aliases and infrastructure associated with the CRPx0 operation are controlled by the threat actor, a Tunisian individual reportedly residing in Volgograd, Russia, which is also the same city referenced on the VariableX website. 

It is important to note that the threat actor identifies himself on some social media profiles with two possible first names. Based on KELA’s investigation, the two names being used are the same individual, rather than two distinct personas. Moreover, the ransomware operation currently appears to be operated solely by the threat actor, with no evidence of a larger team behind the operation, unlike many other established groups.
Ali’s Telegram positive comments
Threat Actor’s personal Telegram with positive comments on the CRPx0 related Telegram channels

» Find out why your organization needs cyber threat intelligence

Bottom Line

KELA assesses with moderate to high confidence that the CRPx0 operation is run by the threat actor, a Tunisian national reportedly residing in Volgograd, Russia. There is a possibility that the threat actor is only an associate of CRPx0, however, based on the available evidence, this currently appears unlikely. The assessment rests on a multi path OSINT chain that converges on the same identity from several independent directions: the Tox ID reused across victim negotiations ties the operation to the "MrAnon00"/DataBreachPlus persona, whose alias history, infrastructure, and service branding (VariableX, Bot99, CryptoStealer, and related scams) repeatedly resolve back to the threat actors real world identifiers.

Multiple corroborating anchors reinforce this assessment.

  • The alino95/alino95x usernames appear across Nairaland and Nulled, with additional links to bot99.co.
  • The Volgograd location independently surfaces through variablex.ru alongside the Russian phone records.
  • The "Batman"/1996 motif recurs across the_batman_96 and TheBatmanCoder, as well as in the DOB identified in Russian leak data.
  • Finally, the operational activity of @yournextgov, which is subscribed to the same CryptoStealer, TrustWallet, and TheSwapp3r channels associated with CRPx0, provides further supporting evidence.

Contacts & IoCs

Forums

  • Altenens Forum – MrAnon00, comebackagain
  • Nairaland Forum – alino95
  • Nulled Forum – alino95x

Tox

  • 17EB54B8455144E088C7E77F88A97221C319F0CFE4FE306853EEB113EE8DB5607BB6EE481C7C

Telegram

  • @CRPx0 (ransomware operation channel)
  • @DataBreachPlus – ID 5604112668 (aka DataBreachPlus, coinlithic, Mr_Stalingrad, cryptostealerseller1, cryptostealerseller, x0x00xx0x, the_batman_96, TheSwapp3rSuppx, TheSwapp3rSupport, andrew_687)
  • Xray Crypto Miner
  • Flash Token Shop
  • CryptoStealer
  • TrustwalletNightmare
  • XrayCracker
  • CopyGhost
  • @yournextgov – ID 1924340259

Websites and Domains

  • crpx0[.]su
  • tlxoddx4odmc2qvsmtsbgwwsv5j45osb5sox7mz6izxliuju5mkulzad[.]onion
  • xburs4nr6cbuktokhqwefeh5hsjakz6usll5o7z5uhrfcnolakj4ptad[.]onion
  • databreach.space
  • fanonlyatn[.]xyz
  • caribb[.]ru
  • mekhovaya-shuba[.]ru
  • beboss34[.]ru
  • variablex[.]ru

» Don’t let threat actors take you by surprise.

CRPx0's tooling, lures, and affiliate offers circulated on criminal forums and Telegram channels before most of its victims knew the group existed. That gap is where intelligence changes the outcome.

Request a free trial of KELA’s Cyber Threat Intelligence Platform

Discover & Defend Against Sophisticated Adversaries

Discover how KELA helps organizations uncover, prioritize, and mitigate advanced threats with actionable cyber threat intelligence

Contact Us