CRPx0 Pushes Fake Updates to Trigger Ransomware

The Register Security · Medium sophistication
Last updated August 27, 2026

Researchers say the CRPx0 cybercrime operation uses “ClickFix” lures (fake Windows Update and fake Google reCAPTCHA pages) to trick people into running commands that install ransomware. The group also advertises a white-label ransomware service and claims its victim count rose sharply, with data stolen before encryption and a short deadline to pay before leaks.

Key findings

  • CRPx0 claims its victim count rose to “48 organizations” on its clear-web leak site.
  • Affiliates can use ClickFix delivery with two lures: “a fake Windows Update and a fake Google reCAPTCHA.”
  • The Windows lure tricks users into pasting a PowerShell command into the Run dialog; macOS uses a “curl|bash” command.
  • The malware “steals high-value files before encrypting them” and gives a “48-hour deadline to pay up - or see their files leaked.”
  • Defender guidance emphasizes preventing/monitoring Run dialog abuse and detecting RunMRU traces for ClickFix activity.

Who’s being targeted

  • Commonly targeted roles: All employees, macOS users, Windows users, IT, Security Operations (SOC), Helpdesk.
  • Attack channels: website.
  • Impersonated: Windows Update (Microsoft), Google reCAPTCHA, Software update/troubleshooting assistant (macOS).

Awareness takeaways

  • Train staff: never run copy/paste commands (PowerShell/Terminal) from a web page to “fix” an update or CAPTCHA.
  • Add specific detection and response playbooks for ClickFix traces (Run dialog history and suspicious command patterns).
  • Assume data theft happens before encryption, treat early warning signs as urgent and investigate immediately.
  • Harden backup access so compromised user accounts can’t reach or delete backups.

Red flags to watch for

  • A web page instructs you to run PowerShell commands manually
  • Unusual request to use the Windows Run dialog
  • Security/updates delivered via copy-paste commands instead of normal update tools
  • reCAPTCHA asking you to run commands on your computer
  • Verification step that involves copy/paste execution
  • Mismatch between the site’s request and normal browser-based CAPTCHA behavior
  • Any website instructing macOS users to run “curl | bash”
  • Unexpected Terminal use for routine updates
  • One-liner commands that download and execute code
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re browsing, and suddenly a page says: “Windows Update required: copy/paste this PowerShell command into Run to continue.” That’s ClickFix from a group called CRPx0. They’ve hit 48 organizations by getting people to paste their command into the Windows Run box, which quietly pulls ransomware and steals files before anything gets encrypted. They also use a fake Google reCAPTCHA page that says, “reCAPTCHA verification required: run the provided command to complete the check.” Real CAPTCHAs never make you run PowerShell or Terminal commands, ever. If any website ever tells you to copy a PowerShell or Terminal command to ‘fix’ an update or pass a CAPTCHA, stop immediately and report it to Security, do not run the command.

Similar attacks

Fake GTA VI Leak Pushes 113GB Malware Trap

Fake GTA VI Leak Pushes 113GB Malware Trap

Attackers are abusing excitement around GTA VI leaks by distributing a fake 113GB “playable build” that is mostly empty data with a small malware payload hidden inside. The malware attempts to weaken defenses by adding Windows Defender exclusions and killing security tools, then likely prepares the…

August 24, 2026
Phish Lures Steal Bank Logins via Telegram

Phish Lures Steal Bank Logins via Telegram

The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing…

August 24, 2026
Russian Spy Phish Uses Legit OAuth Logins

Russian Spy Phish Uses Legit OAuth Logins

Google says three suspected Russian cyber-espionage groups are running highly targeted phishing campaigns against people in government, academia, defense, and think tanks in the US and Europe. A key theme is abusing legitimate Google/Microsoft OAuth login flows so the outreach looks real, tricking…

August 21, 2026
Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Fake Zoom/Adobe Updates Drop ScreenConnect Backdoor

Researchers described an active phishing campaign that tricks people with fake Adobe/Zoom update and “document review” themes to install the legitimate ScreenConnect remote-access tool. Once installed, attackers get persistent remote control of the victim’s computer while blending in as normal IT…

August 4, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login pages or fake update screens. The goal was to steal Microsoft 365 credentials and/or trick victims into installing espionage malware,…

August 3, 2026
Fake Claude App and Alert Apps Drive New Scams

Fake Claude App and Alert Apps Drive New Scams

This roundup describes multiple real-world campaigns where attackers trick people into installing malicious software that looks legitimate (a fake Claude desktop app, a fake emergency alert app, and banking-malware phishing). The common pattern is “looks normal, feels urgent,” leading users to…

July 23, 2026