CRPxO — Ransomware Profile

CRPxO runs a ransomware-as-a-service operation that debuted in July 2026 and claimed 37 victims between 9 July and 2 August 2026, weighted heavily toward US organizations with Türkiye a distant second. Its encryptor runs inside a portable Python virtual environment and executes across Windows, macOS and Linux, encrypting local files with a Fernet-wrapped symmetric key while files on remote Windows shares are encrypted with a hard-coded RSA public key. The malware spreads by enumerating other hosts through Active Directory, IP broadcast and the ARP cache on Windows, and by riding passwordless SSH on Linux and macOS.

Also tracked as

Crpx O, CRPx0

IntelFusions coverage (3)

Tools & malware

Recent claimed victims

Vendor research

Read the full analysis on IntelFusions