Also known as: CRPx0, Threat Research Labs, tracked as, Country Motors, fully compromise na yan, represents a financially motivated, modular payload delivery, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Country Honda, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code
CRPxO operates from a modular tool kit that includes droppers, backdoors, packers, and cryptographic components. Their attacks typically begin with reconnaissance and vulnerability scanning of publicly exposed systems, followed by brute‑force credential discovery or spear‑phishing to gain footholds in cloud accounts, corporate networks or internal messaging services. Once inside the network, they deploy ransomware payloads that use a combination of data encryption (T1486) and double extortion tactics—exfiltrating sensitive assets before encryption. The group also monetizes stolen cryptocurrency wallets and performs ‘pig‑butchering’ campaigns. A key feature of CRPxO’s operational design is the heavy reliance on rented or proprietary cloud infrastructure; they build serverless functions, deploy public cloud services, purchase domains and even advertise malware via web ads to obfuscate command‑and‑control traffic. In addition, the actors embed malicious backdoors within container images (AWS AMIs, Azure VMs) and other widely used software containers, enabling persistence and stealth over long periods. Their toolset is supported by in‑house exploits, self‑signed certificates, and a spectrum of legitimate utilities such as PowerShell, netsh, PsExec and web services. These capabilities give CRPxO the flexibility to pivot between attack vectors—whether it’s ransomware on financial institutions, data theft from pharmaceutical companies, or credential hijacking in defense contractors—while complicating detection through cloud‑native C2 channels, obfuscated binaries, and aggressive infrastructure acquisition tactics.
Objectives
Targeted Sectors
Targeted Countries / Regions
Executive Summary
CRPxO is a financially motivated, medium‑sophistication ransomware group leveraging double extortion and crypto‑theft tactics. The actors routinely employ cloud‑based staging, public‑service C2, and online advertising to deliver malware while actively probing and exploiting vulnerable target environments. Recent operations have focused on sectors such as finance, media, healthcare, aviation, telecommunications, defense, and government across the US, UK, Japan, Mexico, Turkey, and Saudi Arabia.
Goals & Targeting
CRPxO is primarily driven by monetary gain, employing double extortion to pressure victims into paying both ransom and a separate fee for deleted data. Their sector focus reflects high-value targets with critical data or customer-facing services: finance, telecommunications, healthcare, aviation, manufacturing, defense and media. CRPxO’s use of cloud infrastructure and public services enables rapid pivoting across geographic regions—US, GB, JP, MX, TR, SA—and mitigates detection by blending traffic into legitimate cloud workloads. Strategically, the group appears to combine opportunistic exploitation with targeted asset theft. By leveraging compromised accounts, they increase their reach while reducing costs through rented resources and advertisement networks. The attacker’s tactics emphasize persistence (persistence in container images), reconnaissance (active scanning, vulnerability discovery) and exfiltration over application‑layer protocols, highlighting a sophisticated but relatively rapid operational tempo. Overall, CRPxO seeks to maximize revenue per infection cycle: encrypt data, threaten its release, and leverage stolen cryptocurrency wallets—all while preserving anonymity through cloud hosting and obfuscated code.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Operational evidence indicates CRPxO campaigns are short‑lived, often lasting days to weeks per target. Victims range from boutique dental practices to large defense contractors, illustrating a willingness to adapt tactics for both low‑profile and high‑visibility targets. Past incidents reveal the group’s penchant for exploiting cloud services—creating or hijacking serverless functions, leveraging public APIs, and embedding malicious containers—to sidestep perimeter defenses. They also use paid online ads to deliver payloads or establish initial footholds, thereby increasing distribution reach while obfuscating the source of infection. The attacker’s tempo is high: reconnaissance occurs quickly after a target is identified, followed by credential reuse or phishing within hours. Ransomware is typically deployed within 24–48 hours of establishing persistence, with data exfiltration and double extortion messaging following closely thereafter.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on multiple reports and observable TTP patterns, providing a moderate to high confidence level for the identified tactics, techniques, and operational behaviors. However, gaps exist in publicly available context regarding detailed internal infrastructure, exact ransomware variants, and long‑term persistence mechanisms. Additional indicators of compromise and threat actor attribution evidence could further solidify the confidence assessment.
CRPxO: THY
Ransomware attack attributed to CRPxO. | Country: TR | Sector: Transportation | Sector: Aviation | Data leaked: 4.2 GB | Source: https://www.ransomware.live/id/VEhZQENSUHhP
Jul 31, 2026
TLP:CLEARNo observed data linked yet.
42
Techniques
45
Tools
153
Campaigns
39
IOCs
0
Observed Data
14
Tactics