HomeSecurityOnlyFans as bait for distributing CRPx0 malware

OnlyFans as bait for distributing CRPx0 malware

A new malware campaign dubbed CRPx0 has come to light, using the promise of free access to OnlyFans accounts. According to analysis by Aryaka Threat Research Labs, it is a highly organized and persistent cross-platform threat targeting systems Windows and macOS, while there are indications that it is being developed and released for Linux.

OnlyFans CRPx0

Social engineering focused on “free content” on OnlyFans

The attack begins with a classic but effective social engineering trick: the promise of free accounts on OnlyFans. Users seeking unauthorized access to premium content are directed to a compressed file named OnlyfansAccounts.zip. The choice of this bait is not accidental, as it targets users who are already more likely to ignore security warnings and risk downloading unknown files.

Inside the file is a shortcut named Onlyfans Accounts.lnk, which appears as a “logical next step” to obtaining the supposed accounts. In reality, this is the malware’s entry point into the victim’s system.

See also: Claude Code: Fake installers install malware

From fake credentials to malware installation

Upon opening the file, the user sees a document titled Accounts.txt, which presents a list of supposedly “50 operational OnlyFans accounts.” Behind this facade, however, the installation of CRPx0 is silently.

The malware establishes a connection to command-and-control (C2) servers, collects information about the system environment, and establishes persistence mechanisms to remain active. In addition, it regularly checks for updates, downloading newer versions of itself when they are available, which indicates a high degree of sophistication and modular design.

OnlyFans as bait for distributing CRPx0 malware

CRPx0 Campaign: Three Main Attack Phases

CRPx0's operation is divided into three main axes: cryptocurrency theft, data extraction, and ransomware. The combination of these creates a double extortion model, where victims are pressured through both data loss and encryption.

Cryptocurrency theft via clipboard hijacking

One of the most characteristic elements of the attack is the monitoring of the system's clipboard. When the user copies a cryptocurrency wallet, the malware automatically replaces it with an address controlled by the attackers. Thus, transactions are redirected without the victim realizing it, leading to immediate financial loss.

See also: TrickMo banking malware for Android adopts TON blockchain

Data extraction and double blackmail mechanism

In the second phase, CRPx0 proceeds to mass-collect data selected by the attackers via the C2. The data includes documents, images, emails, and even sensitive programming or design files. Extracting this information acts as a preparation for blackmail, as the attackers threaten to release it.

Encryption and ransomware with advanced techniques

In the ransomware phase, the system downloads a script (crypter.py) and generates unique encryption keys via AES Fernet-type mechanisms. Files are encrypted and given the extension .crpx0, while specific system folders are excluded to keep the operating system functional.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

At the same time, the desktop wallpaper changes with a blackmail message and payment instructions appear in multiple languages, such as English, Russian and Chinese, reinforcing the international targeting of the campaign.

Attack infrastructure and extortion model

The group behind CRPx0 maintains a leak website, where it claims to have hacked dozens of victims and extracted huge amounts of data. In some cases, the stolen data is being sold for $500 in cryptocurrency, offering “lifetime access” to future leaks.

This model clearly shows a shift from traditional ransomware to a hybrid data commercialization system.

OnlyFans as bait for distributing CRPx0 malware

Broader impacts and strategic targeting

While the attack does not appear to target a specific industry, the use of OnlyFans as a lure suggests that the attackers are targeting a broad audience with an increased risk potential. This strategy relies on mass rather than personalized targeting.

As Aryaka's analysis points out, this is a modular and scalable threat, capable of adapting and escalating from simple theft to full-blown double-extortion operations.

See also: Venmo changes privacy defaults for new users

A new generation of multi-layered cyber threats

CRPx0 is a prime example of a new generation of malware, where social engineering, financial exploitation, and technical sophistication combine into a single attack ecosystem. The use of well-known platforms like OnlyFans as “bait” demonstrates that attackers are now investing more in human behavior than solely in technology, making cybersecurity more critical than ever.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS