Also known as: tracked as, a checkout fee
DatabreachPlus is a sophisticated threat actor that operates as a multi‑stage malware-as-a-service platform. Their core infrastructure relies on an open‑source FastAPI web panel, publicly exposed at 103.241.66[.]238:1337, which manages license keys and distributes staged payloads to infected hosts. The software stack includes clipboard hijacking engines designed to capture cryptocurrency transactions across eight different chains (Bitcoin, Ethereum, Tron, Dogecoin, Litecoin, Solana, Ripple, Bitcoin Cash) and a BIP‑39 seed phrase theft module that steals wallet recovery phrases from local clients. The malware suite also implements a browser credential exfiltration component that harvests saved usernames, passwords and authentication tokens. In the final stage, it deploys a ransomware engine dubbed crpx0, which encrypts user files and delivers extortion demands. Attackers communicate with the C2 infrastructure through three Russian .ru domains pointing to 31.31.198[.]206 on REG.RU hosting, and use end‑to‑end encrypted channels via Telegram, qTox, and ProtonMail. Social engineering is employed using FedEx and OnlyFans themed spearphishing emails that entice victims into downloading malicious attachments or visiting a compromised URL. The operation covers an extensive geography – United States, Canada, India, Pakistan, China, Great Britain, Singapore, Israel, Romania, South Korea, Russia – and spans nearly every major industry including finance, healthcare, defense, education, hospitality, and critical infrastructure. The exposed source code for both the RAT builder and ransomware module suggests a highly modular design that can be quickly forked or adapted by other threat actors. The presence of tiered licensing indicates an intent to sell the tooling to other criminals, further amplifying the operational scope. goals_targeting":"DatabreachPlus pursues high‑value financial gain through dual revenue streams: direct cryptocurrency theft and ransomware extortion. By targeting ubiquitous sectors such as finance, healthcare, education, and government, the actors maximize the likelihood of uncovering valuable credentials and sensitive data that can be leveraged or sold on underground markets. The choice of FedEx and OnlyFans social‑engineering themes underscores a focus on legitimate corporate or entertainment accounts to lower suspiciousness. Target countries are selected based on their large population base and perceived willingness to pay ransoms, combined with a preference for jurisdictions with weaker regulatory oversight. key_capabilities":["Multi‑stage malware incorporating clipboard hijacking of 8 major cryptocurrencies","BIP‑39 seed phrase theft from wallet clients","Browser credential harvesting and exfiltration","Delivery of crpx0 ransomware engine for file encryption","FastAPI web panel enabling command‑and‑control and license enforcement","Open‑source code exposure facilitating rapid cloning","FedEx/OnlyFans themed spearphishing campaigns","Telegram/qTox/ProtonMail based C2 communication","Tiered Malware‑as‑a‐Service licensing model","Use of Russian .ru domains and bullet‑proof hosting for resilience"], mitre_techniques":["T1566.001","T1115","T1059.003","T1078","T1486","T1105","T1041","T1027","T1064","T1556.002"], mitre_tactics":["Initial Access","Execution","Persistence","Privilege Escalation","Credential Access","Exfiltration","Impact"], asociated_tools":["Crpx0 Ransomware","Clipper Wallet Stealer","Custom FastAPI RAT Builder (RAT)","Telegram C2 Service"], campaign_insights":"DatabreachPlus operates largely as a MaaS model, publishing the source code of its core components publicly to enable rapid replication. The actor employs a multi‑stage delivery chain: initial spearphishing lures themed around FedEx or OnlyFans trigger the download of a lightweight downloader; this in turn deploys the RAT builder and cryptocurrency clipper modules on the victim system. Subsequent stages involve harvesting credentials, exfiltrating wallet data, and finally delivering the crpx0 ransomware payload. Operations have demonstrated consistent C2 stability through .ru domains and fast‑flux DNS techniques, enabling persistent communication with compromised hosts over extended periods. The actor’s geographic diversity—spanning North America, Eurasia, and South Asia—suggests a scalable threat model that is not confined to a single nation or industry.", "ioc_patterns":["Domain-based DNS C2 over suspicious .ru domains resolving to 31.31.198.206","Exposed FastAPI panel at 103.241.66[.]238:1337 with credential‑protected access","Clipboard hijacking delivering numerous cryptocurrency wallet addresses (BTC, ETH, TRX, DOGE, LTC, SOL, XRP, BCHA)","Spearphishing emails using FedEx and OnlyFans themed attachments or links","Ransomware module crpx0 encrypting files across victim machines","Use of Telegram, qTox, ProtonMail for command & control communications","Tiered licensing system requiring license keys to activate malware functionality"], recommended_actions":["Implement network-level blocking of outbound DNS queries and HTTP(S) traffic to known .ru domains and 31.31.198[.]206.","Deploy endpoint detection that flags clipboard hijacking and abnormal wallet data exfiltration behaviors.","Enforce strict credential hygiene: two‑factor authentication for all systems, especially those handling financial or healthcare data.","Regularly audit web applications to detect exposed C2 panels such as FastAPI instances.","Maintain clean, verified backups and enable ransomware recovery drills.","Provide employee security awareness training focusing on FedEx/OnlyFans‑themed phishing.","Apply network segmentation to limit lateral movement from compromised endpoints.","Patch systems promptly to mitigate known vulnerabilities that could be exploited for initial access."], "suggested_tags":["APT","Malware-as-a-Service","Ransomware","Cryptocurrency Theft","Financial Services","Healthcare","Government","Education","Retail"], confidence_assessment":"The intelligence is drawn mainly from the public description of DatabreachPlus and a single external reference to a similar threat on an OffSeq radar page. While component details—such as clipboard hijacking, Crpx0 ransomware, FastAPI panel, and .ru domain usage—are well‑documented in the actor’s own disclosures, there is limited corroborating evidence from independent industry reports or vendor alerts. The absence of a formal attribution or detailed incident response logs introduces uncertainty regarding the precise prevalence, operational tempo, and impact magnitude of this threat. Future monitoring for newly published indicators and confirmation via security feeds will be necessary to refine confidence levels.", "sources":["https://radar.offseq.com/threat/twizadmin-multi-stage-crypto-clipper-infostealer-r-28b2953c","https://www.wired.com/story/149-million-stolen-usernames-passwords/"]}
Targeted Sectors
Targeted Countries / Regions
Executive Summary
DatabreachPlus is a financially motivated, multi‑stage malware actor that combines cryptocurrency wallet theft, credential exfiltration, and ransomware delivery. They leverage a FastAPI‑based RAT builder with license enforcement to target Windows/macOS victims through FedEx/OnlyFans‑themed phishing campaigns across broad sectoral ranges. The operation’s exposed source code and use of a commercial ransomware module (crpx0) highlight its Malware‑as‑a‑Service model.
Enhanced Description
No campaigns linked yet.
No observed data linked yet.
2
Techniques
46
Tools
0
Campaigns
47
IOCs
0
Observed Data
1
Tactics