Business Insights Cybersecurity Blog by Bitdefender

Bitdefender Threat Debrief | August 2026

Written by Jade Brown | Aug 12, 2026

CRPx0 Ransomware: A Look Beyond the Rising Claims

This edition of the Bitdefender Threat Debrief covers several current events in the ransomware threat landscape, including CRPx0’s recent rise and Top Groups. Other events featured in this release include an update on The Gentlemen, INC Ransom’s recent exploitation activity, and more.

As ransomware continues to evolve, our goal with this monthly Bitdefender Threat Debrief is to help you stay ahead of the curve. To do this, we combine information from openly available sources (OSINT) - things like news reports and research – with data we gather by analyzing Data Leak Sites (DLSs), websites where ransomware groups post details about their victims. It is important to remember that we can't independently verify all of these claims but are confident in the trends we see over time.

For this month's report, we analyzed data from July 1 to July 31 and recorded a total of 873 claimed ransomware victims. This was the third-highest total in the last 12 months.

Featured Story: CRPx0 Ransomware - A Look Beyond the Rising Claims

What Happened?

CRPx0’s ransomware activity was identified in June 2026. The group was getting very little traction and had less than 10 reported victims. However, the group’s activity picked up in July, resulting in a total of 46 victims. On the surface, CRPx0 appears to be a standout among threat actors. However, the group's behavior raises questions about their operational growth, alleged victims, and current business models.

Victimology and Business Models

In June, CRPx0 claimed victim organizations in healthcare, primarily small-sized dental practices. This rapidly changed in less than two weeks' time as CRPx0’s victims expanded to include larger organizations in the technology and financial services industries.

While many of the victims that CRPx0 has claimed are based in the United States, the group has a growing number of victims based in Turkey. The publishing of victims in this demographic region in close succession mirrors a similar pattern seen with Qilin’s Korean Leaks operation. Still, at the time of this release, there is no information linking that activity to a widespread supply chain compromise of Turkish organizations.

CRPx0 was initially believed to be a Ransomware-as-a-Service (RaaS) group. However, there are a few unusual elements tied to the marketing of their RaaS program. The most notable one is the group’s insistence on supporting white-label operations. CRPx0 provides RaaS buyers with the resources to manage ransomware campaigns under the buyer’s name and markets a 100% profit-sharing model, allowing buyers to keep all profits.

A 90% profit-sharing model was once the highest reported percentage, with groups like The Gentlemen taking the lead in offering their affiliates more than competing groups. However, an offer of 100% sounds too good to be true, especially when paired with the $10,000 one-time subscription fee required to access the RaaS platform.

What’s also unusual is CRPx0’s simultaneous marketing of a Hacking-as-a-Service (HaaS) program. The program includes data breach, network compromise, and other services intended to disrupt businesses.

CRPx0’s departure from an RaaS-only model could be a strategic move to attract new recruits, or a scam targeting a range of affiliate hopefuls seeking cybercrime services. While information about the group’s business models is limited, it’s important to note that, outside white-label operations, an affiliate page lists a 70% profit-sharing model.

Suspicions Concerning Claimed Victims

There is uncertainty surrounding whether CRPx0 may have inflated the number of claimed victims to develop trust and draw in RaaS buyers and other communities. A surge of victims within a couple of weeks with near synchronous ransom countdowns may be attributed to scam behavior. However, the same activity could also develop as a result of extended access to multiple data breach sources, allowing the threat actor to strike in a near synchronous manner. In addition, if CRPx0 is not the group responsible for the initial data breach of several of their claimed victims and instead received the victim datasets from an external source, it makes their claims far less credible.

What Tactics are Unique and What are the Implications?

CRPx0 uses a dynamic toolset, including Living off the Land (LOTL) techniques and payloads, to encrypt data. On its own, this is not a unique pattern of attack. Neither is the fact that the group has employed another tactic adopted by other threat actors: using ClickFix lures embedded in fake CAPTCHA webpages. However, going beyond the method used to drop payloads, one of CRPx0’s attack objectives involves crypto theft, which sets the group apart from other ransomware groups.

The threat actor has a payload equipped with a clipper and a module that extracts the seed phrase or key tied to a crypto wallet, which may cycle through an attack with fewer risks and barriers. The crypto theft focus presents an alternative solution to a challenge that many cybercriminals encounter: an over expenditure of time and resources used on delayed or unmet ransom demands.

It also illustrates that prioritizing operations involving infostealers and other initial access vectors combined with ransomware can be far more effective than a reliance on the exploitation of software vulnerabilities and the deployment of encryptors, which risk detection. As CRPx0 develops their career portfolio, other threat actors may attempt to adopt similar techniques.

This is a reminder that organizations should balance detection capabilities in preparation for different types of compromises, configuring technologies to detect and block malicious behavior that aligns with both crypto theft and encryption processes.

Watch the Live Discussion

Our expert panel covered this emerging situation and other notable ransomware developments during our monthly Ctrl-Alt-Decode debrief.

Other Notable Ransomware News

Now, let’s explore the notable news and findings since the previous Threat Debrief.

  • The Gentlemen claims the top spot again: Last month, The Gentlemen moved into first place on our ranking of top ransomware groups. The Gentlemen’s rise was attributed to several factors, including a willingness to adapt playbook techniques they’d leveraged for Qilin, the propensity for affiliate crossover between the two groups, and The Gentlemen’s use of AI to enhance tooling and methodology. The group has continued to claim an influx of victims from broader regions, including Southern Asia.
  • INC Ransom chains SonicWall SMA 1000 vulnerabilities to establish root access: Several reports have identified that INC Ransom has exploited CVE-2026-15409 and CVE-2026-15410 since June of this year. Threat actors exploit these vulnerabilities, associated with the SonicWall VPN appliance, to both elevate their level of access to credentials and password configurations and database files, and also to execute malware in the next stage of the attack. The malware, KNUCKLEBALL and ORANGETAIL, allows the threat actor to operate with a greater level of persistence with the use of a web proxy and an active web shell. Organizations with SonicWall SMA 1000 appliances are advised to ensure that their systems are using the latest version, and they should continue to review vendor notices for additional recommendations and updates.
  • Global Secret Group emerges with code built from LockBit Black: GSG is a ransomware group that has recently updated their data leak site. While the group has received scrutiny for their victim claims, with victim datasets surpassing 100,000, GSG has notably claimed victims in the energy and utilities industries. This aspect combined with their records of different victim databases establishes that GSG is an organized syndicate. This makes the group different than a copycat threat actor that appears and then fades out because they are relying on an iteration of leaked ransomware code. Those types of copycat groups lack the ability to invent and advance their own tooling and attack practices.
  • LAPSUS$ announces an exit from the ransomware ecosystem: This is not their first time making such an announcement and it’s unlikely to be their last. It might even be a ploy before a new partnership, a site relaunch, or a successful campaign is publicized. While LAPSUS$’s victims in 2026 thus far have included a higher representation of organizations in the technology industry, the group’s prioritization of identity-focused compromise has a high impact beyond the technology and IT support service providers.

Top 10 Ransomware Families

Bitdefender's Threat Debrief analyzes data from ransomware data leak sites, where groups publicize their claimed number of compromised organizations. This approach provides valuable insights into the overall activity of the RaaS market. However, there is a trade-off: while it reflects attackers' self-proclaimed success, the information comes directly from criminals and may be unreliable. Additionally, this method captures the number of victims claimed, not the actual financial impact of these attacks.

The Top 10 ransomware groups in July include The Gentlemen, Qilin, and CRPx0. Qilin had a rise in victims after their drop last year. And, another group gaining attention, Global Secret Group, claimed 31 victims, placing in the 7th rank.

Top 10 Most Attacked Regions

Ransomware gangs prioritize targets where they can squeeze the most money from their victims. In many cases, this means focusing on developed countries with higher projected growth rates. Threat actors may also execute strategic attacks that unfold during geopolitical conflicts or periods of social unrest.

Argentia claims the 8th rank in the Top 10 Regions: Over the past few months ranks 8 to 10 were often claimed by East Asian regions. In July, ransomware groups claimed 21 victims based in Argentina. The groups claiming victims based in Argentina included the top groups such as The Gentlemen, Qilin, and DragonForce.

Top 10 Most Attacked Industries

Ransomware gangs may target organizations in critical infrastructure sectors, select other organizations that offer services tailored to consumers, or attack organizations that fall into both categories. Understanding the trends and ramifications associated with specific industries, and how specialized services and clientele are impacted is crucial for assessing risk. Here are the Top 10 industries affected by ransomware attacks.

In July, the construction industry fell to the 5th-most-affected industry by ransomware. Technology and healthcare climbed to the 2nd and 3rd ranks. There was also an increase in the number of victims claimed in the financial services industry.

 We'll discuss more about this emerging situation and other notable ransomware developments during our monthly Ctrl-Alt-Decode debrief

About Bitdefender Threat Debrief

The Bitdefender Threat Debrief (BDTD) is a monthly series analyzing threat news, trends, and research from the previous month. Don’t miss the next BDTD release, subscribe to the Business Insights blog, and follow us on Twitter. You can find all previous debriefs here.

Bitdefender provides cybersecurity solutions and advanced threat protection to hundreds of millions of endpoints worldwide. More than 180 technology brands have licensed and added Bitdefender technology to their product or service offerings. This vast OEM ecosystem complements telemetry data already collected from our business and consumer solutions. To give you some idea of the scale, Bitdefender Labs discover 400+ new threats each minute and validate 30 billion threat queries daily. This gives us one of the industry’s most extensive real-time views of the evolving threat landscape.

We would like to thank Bitdefenders Stefan Hanu, Mihai Leonte, Gabriel Macovei, and Andrei Mogage for their help putting this report together.