CRPx0 is a cyber extortion and ransomware-linked threat actor active by mid-2026. The group is known for coercive post-compromise monetization, including operating public leak sites on both the clear web and dark web and listing victims that allegedly refused to pay. It has also been reported to escalate pressure by offering stolen victim data for sale after payment deadlines expire, indicating a data-theft extortion model and use of a leak site as part of its victim pressure strategy. CRPx0 has been associated with social-engineering-based initial access, including lures offering free OnlyFans accounts to entice targets into clicking malicious links that deploy malware. This demonstrates use of themed phishing or lure-based delivery for initial compromise, followed by malware execution and extortion. Public reporting also places CRPx0 among the more active extortion actors in July 2026 by claimed victim volume. High-confidence reporting supports characterizing CRPx0 as a financially motivated criminal actor focused on extortion. Specific national affiliation, organizational structure, and stable sub-group taxonomy are not established from the available information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Extortion-focused threat actor operating a leak site and using lures offering free OnlyFans accounts to trick victims into clicking malicious links that deploy malware; it has publicly listed victims that did not pay.
A ransomware group listed among the more active actors in July 2026, but not a primary focus of the piece.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.