A new malware campaign dubbed CRPx0 has come to light, using the promise of free access to OnlyFans accounts. According to analysis by Aryaka Threat Research Labs, it is a highly organized and persistent cross-platform threat targeting systems Windows and macOS, while there are indications that it is being developed and released for Linux.

Social engineering focused on “free content” on OnlyFans
The attack begins with a classic but effective social engineering trick: the promise of free accounts on OnlyFans. Users seeking unauthorized access to premium content are directed to a compressed file named OnlyfansAccounts.zip. The choice of this bait is not accidental, as it targets users who are already more likely to ignore security warnings and risk downloading unknown files.
Inside the file is a shortcut named Onlyfans Accounts.lnk, which appears as a “logical next step” to obtaining the supposed accounts. In reality, this is the malware’s entry point into the victim’s system.
See also: Claude Code: Fake installers install malware
From fake credentials to malware installation
Upon opening the file, the user sees a document titled Accounts.txt, which presents a list of supposedly “50 operational OnlyFans accounts.” Behind this facade, however, the installation of CRPx0 is silently.
The malware establishes a connection to command-and-control (C2) servers, collects information about the system environment, and establishes persistence mechanisms to remain active. In addition, it regularly checks for updates, downloading newer versions of itself when they are available, which indicates a high degree of sophistication and modular design.

CRPx0 Campaign: Three Main Attack Phases
CRPx0's operation is divided into three main axes: cryptocurrency theft, data extraction, and ransomware. The combination of these creates a double extortion model, where victims are pressured through both data loss and encryption.
Cryptocurrency theft via clipboard hijacking
One of the most characteristic elements of the attack is the monitoring of the system's clipboard. When the user copies a cryptocurrency wallet, the malware automatically replaces it with an address controlled by the attackers. Thus, transactions are redirected without the victim realizing it, leading to immediate financial loss.
See also: TrickMo banking malware for Android adopts TON blockchain
Data extraction and double blackmail mechanism
In the second phase, CRPx0 proceeds to mass-collect data selected by the attackers via the C2. The data includes documents, images, emails, and even sensitive programming or design files. Extracting this information acts as a preparation for blackmail, as the attackers threaten to release it.
Encryption and ransomware with advanced techniques
In the ransomware phase, the system downloads a script (crypter.py) and generates unique encryption keys via AES Fernet-type mechanisms. Files are encrypted and given the extension .crpx0, while specific system folders are excluded to keep the operating system functional.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
At the same time, the desktop wallpaper changes with a blackmail message and payment instructions appear in multiple languages, such as English, Russian and Chinese, reinforcing the international targeting of the campaign.
Attack infrastructure and extortion model
The group behind CRPx0 maintains a leak website, where it claims to have hacked dozens of victims and extracted huge amounts of data. In some cases, the stolen data is being sold for $500 in cryptocurrency, offering “lifetime access” to future leaks.
This model clearly shows a shift from traditional ransomware to a hybrid data commercialization system.

Broader impacts and strategic targeting
While the attack does not appear to target a specific industry, the use of OnlyFans as a lure suggests that the attackers are targeting a broad audience with an increased risk potential. This strategy relies on mass rather than personalized targeting.
As Aryaka's analysis points out, this is a modular and scalable threat, capable of adapting and escalating from simple theft to full-blown double-extortion operations.
See also: Venmo changes privacy defaults for new users
A new generation of multi-layered cyber threats
CRPx0 is a prime example of a new generation of malware, where social engineering, financial exploitation, and technical sophistication combine into a single attack ecosystem. The use of well-known platforms like OnlyFans as “bait” demonstrates that attackers are now investing more in human behavior than solely in technology, making cybersecurity more critical than ever.
