Red Hot Cyber
Cybersecurity, Cybercrime News and Vulnerability Analysis

“We Steal Your Data, Then You Decide”: RHC Interviews the Ransomware Cyber Gang CRPx0

3 September 2026 09:16

CRPx0 present itself as a peculiar group, while they self-define as “RaaS” their operative model and service offering is oriented on a strong focus on exfiltration operations. Some of their operations have been publicly reported 1 showcasing an in-house tools development and multi-stage malware chains. Their C2 is used for both operative tasks and impact ransomware phases, moreover other direct monetization modules have been reported like crypto-wallet seed extraction and exfiltration.

The group’s first DLS listing was observed in July 2026 with more than 30 victims published just in that month. The traditional extortion processes are just part of CRPx0 monetization model, they also offer “Whitelabelling” service and Hacking-as-a-Service” products. These services requires a safe infrastructure and meticulously planned setup, this is what urged us to contact CRPx0 directly and ask them some questions about their work.

The floor to CRPx0

1) RHC: Thanks for joining us on RedHotCyber, crpx0! Before we dive in, we’d like to give you a moment to introduce yourself to our readers. What is crpx0, and how did it come to be? Is there a specific distinction between your group and other ransomware operations? From your perspective, what sets you apart from other ransomware actors? Any past experience that you consider a career achievement?

Advertising

CRPX0: CRPxO is a professional Ransomware-as-a-Service operation. We focus on data exfiltration, not encryption. Our approach is simple: we compromise networks, steal data, and give organizations a clear choice—pay to delete the data, or watch it get published. What sets us apart is our efficiency and our strict adherence to our own rules. We are a business, and we treat our victims as counterparties in a transaction, not as targets for destruction. Our biggest achievement to date is the scale of our operations and the credibility we’ve built. Our leak site speaks for itself.

2) RHC: What is your main driving force? Is it financial gain, political or social motives, or a desire for notoriety?

CRPX0: Financial gain is the primary driver. We are not politically motivated. We are a business that provides a service to our affiliates and a solution to our victims. The ransomware ecosystem is a market, and we are a major player in it. Our reputation for professionalism is what keeps affiliates joining and victims negotiating.

3) RHC: The number of victims listed on your leak site is growing rapidly. Is this expansion driven by a specific affiliate recruitment model? The barrier to entry—costing just $333—seems highly attractive and effective for early-stage growth in a RaaS operation. Do you have any comments on that?

CRPX0: Our growth is a direct result of our affiliate program. We have designed it to be low-risk and high-reward for affiliates. The $333 entry fee is a strategic decision—it is low enough to attract serious operators but high enough to filter out time-wasters. We provide a full-service platform: payload, C2 infrastructure, leak site, and negotiation support. Affiliates just need to bring the targets. This model has allowed us to scale rapidly and consistently.

Advertising

4) RHC: A fixed 30% cut is fairly high compared to some traditional affiliates, but you attribute this to your ‘whitelabel’ service offerings. Given the heavy infrastructure and hosting overheads, how hard is it to maintain profitability?

CRPX0: The 30% cut is a reflection of the value we provide. We are not just a payload builder. We handle the entire backend: hosting, infrastructure, leak site management, and negotiations. This allows our affiliates to focus on what they do best: gaining initial access. The overhead is significant, but the volume of our operations ensures profitability. It is a scalable and sustainable model.

5) RHC: In terms of affiliate numbers, do you plan to keep expanding indefinitely, or do you have a cap you prefer not to cross?

CRPX0: We have no hard cap on affiliates. Our infrastructure is designed to scale. However, we prioritize quality over quantity. We vet our affiliates and only accept those who have proven capability. A few skilled operators are far more valuable than a large number of unprofessional ones.

6) RHC: Which operations do you handle strictly in-house, and which functions do you outsource to third parties?

CRPX0: All core operations are handled in-house: payload development, C2 infrastructure, leak site maintenance, and negotiations. This gives us full control over the quality and security of our operations. We do not outsource critical functions

7) RHC: Security researchers managed to expose parts of your backend online—including source code and administrative panels. Was this an accepted risk, or an oversight you only realized after it was leaked? How has this impacted your infrastructure setup moving forward?

CRPX0: We operate in a high-risk environment. A certain level of exposure is an accepted risk. However, we continuously adapt and improve our infrastructure. Any leak is a learning opportunity. We have since hardened our systems and moved to a more resilient setup. This is a constant game of cat and mouse, and we intend to stay ahead.

8) RHC: One source claims that roughly 74 victims were taken down from your leak site after appearing there, though we couldn’t cross-verify that exact count. Do you actually remove listings from the site, and what triggers a removal? What is your standard process for updating or deleting a post based on how negotiations wrap up?

CRPX0: Yes, we remove listings. A listing is a tool for negotiation, not a permanent public shaming. When a victim pays and the data is deleted, we remove their entry. This is a standard part of our protocol. We are professionals, not vandals. Our process is clear: we publish a notice of breach, negotiate a settlement, and upon payment, we delete both the data and the public listing.

9) RHC: Given the rapid growth in your target list, could you give us an assessment of the security levels you’ve encountered in your operations? Do you have any specific technical preferences or areas you specialize in, operationally speaking?

CRPX0: Our targets are primarily medium-sized businesses in regulated sectors—healthcare, legal, finance, and aerospace. These are organizations that have valuable data, and a genuine financial and reputational incentive to protect it. We have encountered a wide range of security postures, from excellent to non-existent. Our operational preference is for speed and efficiency. We move quickly from compromise to exfiltration, which minimizes the chance of detection. We favor phishing and credential theft. We’re not looking for advanced persistent threats; we are looking for quick wins.

10) RHC: Could you tell us more about your white-labeling service? This type of offering seems to be gaining traction very quickly, but beyond a 100% profit share, you also promise “Anti-takedown & OPSEC hardening.” How can you realistically deliver on a guarantee like that within standard operational timeframes?

CRPX0: Our white-label service is for affiliates who want to run their own brand. They keep 100% of the profit, and we handle the infrastructure. The ‘anti-takedown & OPSEC hardening’ is not a guarantee, but a commitment to best practices. We use decentralized hosting, multiple domains, and rapid response protocols. It’s not magic, just rigorous operational discipline.

11) RHC: If you were the CISO of a company you knew could be a future target for CRPx0, which three aspects of its security would you strengthen first?

CRPX0:  If I were a CISO, I’d focus on three things: 1) Zero-trust architecture — assume breach and limit lateral movement. 2) MFA enforcement — many breaches start with compromised credentials. 3) Offline backups — not accessible from the network. If you have those three things, you make yourself a much harder target.

12) RHC: You emphasize OPSEC as a core pillar of your RaaS operation. What are your thoughts on recent law enforcement operations, and how do you manage potential operational risks in your line of work?

CRPX0: Law enforcement operations are part of the landscape. We follow their activity, but we don’t alter our core approach. Operational security is our primary concern. We compartmentalize information, use encrypted communications, and limit exposure. We are aware of the risks, and we manage them professionally.

13) RHC: You’ve been linked to the OnlyFans campaign—was that your own operation, an affiliate’s work, or did someone simply use your malware?

CRPX0: We do not comment on specific campaigns or affiliations. We operate with a strict need-to-know basis. Our business model is about providing a platform, not discussing operational details.

14) RHC: Why this initial focus on dental practices and pediatric clinics—organizations with virtually zero IT budget? Are they just easy targets, or is there a regulatory leverage strategy at play? Do you have any restrictions on using your ransomware against healthcare or critical infrastructure?

CRPX0: We target any organization that holds valuable data and is likely to pay. Dental and pediatric clinics are in healthcare, which is a regulated industry. They have patient data (PHI). They are subject to HIPAA. They have a strong incentive to avoid a public data leak and a regulatory nightmare. They are not ‘easy targets’ because of their IT budget, but because of the leverage we gain from the data they hold. We do not restrict targets, but we do avoid critical infrastructure.

15) RHC: Failure is part of the process—do you have a past operational setback that taught you a valuable lesson? What was it, and what did you learn from it?

CRPX0: Early on, we relied too much on a single C2 infrastructure. A takedown operation disrupted a campaign. We learned to decentralize. We now use multiple, redundant systems. Redundancy and rapid recovery are essential in this business.

16) RHC: Has a victim or incident response firm ever impressed you during negotiation chat by outsmarting your team or finding an unexpected loophole?

CRPX0: No. We have encountered professional incident response teams, but they are following a standard playbook. They cannot negotiate their way out of a data breach once the data is exfiltrated. The leverage is ours

17) RHC: What’s your take on the current trend of ransomware groups abandoning encryption entirely to focus 100% on pure data exfiltration and extortion? Is it a temporary trend or do you see a new meta?

CRPX0: The trend toward pure data extortion is a natural evolution. Encryption is loud and slow. Data exfiltration is silent and fast. It also gives us the leverage of a public leak site. This is not a temporary trend; it is the future. Pure data exfiltration is more efficient, less risky, and offers the same or better payment rates.

18) RHC: No one stays on top of the ransomware game forever without the exit strategy catching up to them. What’s CRPx0’s long-term plan? Do you see yourselves running this infrastructure indefinitely, or are you building toward a final ‘retirement’/’endgame’ day?

CRPX0: We are building a sustainable operation. We don’t have a fixed end date. The exit strategy for our operators is to have a legitimate business ready when the time comes. For now, we are focused on growth and efficiency. We will adapt as the ecosystem changes.

19) RHC: Do you actively recruit insiders within target organizations, or do you view dealing with unvetted corporate ‘moles’ as too much of an operational security risk?

CRPX0: We do not actively recruit insiders. It introduces too many variables and is a significant OPSEC risk. We prefer technical compromise—exploiting vulnerabilities and using social engineering. It is more predictable and easier to control.

20) RHC: Your business model relies entirely on granting access to third-party affiliates who could easily be law enforcement plants, rival operators, or careless amateurs. How do you vet people inside your circle, and how do you handle it when a trusted affiliate turns out to be an insider working against you?

CRPX0: Vetting affiliates is a process of building trust. We start with small collaborations and gradually increase access. We monitor their activity. If an affiliate is compromised or becomes an insider threat, we cut them off immediately. We have contingency plans for affiliate misconduct.

21) RHC: Thanks for taking the time from your work for us, we appreciate your collaboration. Our goal with pieces like this is to give our readers a reality check. Security is a cold, hard technical discipline. If defenders want to win, they need to be technically sharper than operations like yours. Consider this slot your opportunity to say whatever you want with absolute freedom. Is there a message you want to leave with our audience or with the organizations next on your DLS list?

CRPX0: Our message to defenders is simple: prepare for the inevitable. A breach is a matter of when, not if. Focus on rapid detection, containment, and recovery. Paying us is one option, but investing in robust security is the better long-term strategy. To our future victims: if you find yourself on our leak site, contact us quickly. The process is designed to be efficient. The sooner you engage, the sooner we can resolve this.


Follow us on Google News to receive daily updates on cybersecurity. Contact us if you would like to report news, insights or content for publication.

RHC Dark Lab 1 1 300x298
RHC Dark Lab is a group of experts from the Red Hot Cyber community dedicated to Cyber Threat Intelligence led by Pietro Melillo. Participating in the collective, Sandro Sana, Alessio Stefan, Raffaela Crisci, Vincenzo Di Lello, Edoardo Faccioli. Their mission is to spread knowledge about cyber threats to improve the country's awareness and digital defences, involving not only specialists in the field but also ordinary people. The aim is to disseminate Cyber Threat Intelligence concepts to anticipate threats.