Security1 distinct publisher3 min readPublished
Bitdefender logged 873 claimed ransomware victims in July, the third-highest month in a year. A brand that barely existed in June supplied 46 of them, on a leak site the analysts say they cannot fully verify.
The Watch · Security desk

security
ClickFix lures now paste an msiexec command that installs legitimate software to sideload a DLL1 distinct publisher
security
PavinLoader: the lures keep changing, the MSBuild stage does not1 distinct publisher
build
ClickFix operators moved the payload into text only the summarizer can see1 distinct publisher
leadership
Fake macOS troubleshooting posts route infostealers past Gatekeeper1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
White-label is the detail that breaks the counting. CRPx0 sells buyers the resources to run campaigns under the buyer's own name [9], so the brand printed on a ransom note carries no fixed relationship to the crew that got in. A leak site is a marketing surface. The name on it is the cheapest part to change.
The economics run the same direction. The advertised 100 percent profit share [10] sits ten points above the 90 percent Bitdefender describes as the previous high, offered by groups such as The Gentlemen [11][2]. Behind that headline number, an affiliate page lists 70 percent [12], a 30-point spread between the pitch and the documented rate [3]. The fixed item is the $10,000 one-time subscription fee for platform access [10]. A seller who collects nothing from ransoms and everything at signup is paid for the appearance of volume. Bitdefender reads the move off an RaaS-only model as either recruitment or a scam aimed at affiliate hopefuls [18], and notes the group is marketing a separate Hacking-as-a-Service line covering data breach and network compromise [13].
Bitdefender offers two readings of July's near-synchronous ransom countdowns and leaves the question open between them: inflation to build trust with prospective buyers [14], or real access to several breach datasets at once, struck in parallel [15]. Both readings damage the number. If CRPx0 did not run the original intrusions and received victim data from an outside source, Bitdefender says the claims are far less credible [16].
Arithmetic on the leaderboard: 46 of 873 is 5.3 percent of everything claimed in July [1], from a group that had under ten listings the month before [3], a rise of at least 4.6 times in four weeks [4]. That single brand moves the monthly total more than most established operations, and the growth came with a client-base change from small dental practices to larger technology and financial services organisations inside two weeks [5].
The Turkish cluster is the clearest test. Victims there were published in close succession, which Bitdefender says resembles Qilin's Korean Leaks operation [7], and it states plainly that there is no information tying the activity to a widespread supply chain compromise of Turkish organisations [8]. The pattern is there. The cause is not.
The tooling matches what everyone else is running, which leaves little to sort on. Living off the Land payloads for encryption and ClickFix lures on fake CAPTCHA pages are, by Bitdefender's own account, not unique to this group [17]. What separates a capable operation from a reseller is the intrusion evidence in the victim's logs, not the row count on a monthly chart that its publisher says it cannot independently verify [2].
Ranked by verification strength, evidence, and original report placement.
Bitdefender analyzed data from July 1 to July 31 and recorded a total of 873 claimed ransomware victims, the third-highest total in the last 12 months.
Bitdefender says it combines open source intelligence with data gathered by analyzing ransomware data leak sites, cannot independently verify all of the claims, but is confident in the trends it sees over time.
CRPx0 ransomware activity was identified in June 2026, when the group had less than 10 reported victims.
CRPx0's activity picked up in July 2026, resulting in a total of 46 victims.
In June CRPx0 claimed victims in healthcare, primarily small-sized dental practices, and in less than two weeks expanded to larger organizations in the technology and financial services industries.
Many CRPx0 victims are based in the United States, and the group has a growing number of victims based in Turkey.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor, counting the criminals' own posts
The chain of custody here is short and entirely internal: Bitdefender read a leak site, counted what was posted, and told readers it cannot verify those posts. No victim is named, no incident response confirms a single encryption event, and the sharpest interpretive lines are framed as open questions rather than findings. What is solid is the arithmetic on the postings themselves — 46 of 873, up from under 10 — and the observable content of the group's own sales pages.
Volume on the leak site, silence everywhere else
Forty-six postings in a month is real traction for a two-month-old brand, and the sector jump from dental offices to finance and technology names is the kind of movement that usually means someone found working access. But the thing being sold — white-label kits at $10,000 — has no visible buyer. Nobody in this reporting has identified an affiliate, a campaign run under a buyer's brand, or a second group using the toolset. Uptake of the crime is inferred from the seller's own advertising.
The loudest number is contradicted two paragraphs later
The overstatement is the criminals', not the analysts'. A 100 percent profit share sits behind a $10,000 door, ten points above what any group had previously offered, and CRPx0's own affiliate page quotes 70 percent — a 30-point gap in one operation's marketing. Add dozens of victims appearing within a fortnight on countdowns that expire almost together, and the plain reading is a reputation being manufactured. Bitdefender deserves credit for saying so itself; the gap sits between what the leak site asserts and what anyone can show.
Both the seller and the counter have something to gain
Two sets of interests shape this record. CRPx0 profits from looking prolific — that is exactly the motive Bitdefender names when it wonders whether the list is padded. And Bitdefender publishes this monthly as business insights, ending on a recommendation that organizations tune detection for crypto theft alongside encryption, which is a product-shaped conclusion from a company that sells detection. Neither interest makes the reporting wrong; both explain why the caveat about unverifiable claims matters more than usual.
Confident about the shape, not the substance
We can say with some assurance what this story is: a single vendor's monthly count, a fast-rising brand inside it, and a sales pitch that contradicts itself. What we cannot say is whether 46 organizations were actually attacked, whether anyone bought the kit, or which of Bitdefender's two explanations for the timing is right — and no second source exists to settle any of it. Our reading would move quickly on one confirmed victim or one independent count.