CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group Lists Hyundai Turkey Assessment Data on Dark Web Leak Site — Threadlinqs Intelligence
As of 2026-08-15, CRPx0 (DataBreachPlus) Double-Extortion Ransomware Group Lists Hyundai Turkey Assessment Data on Dark Web Leak Site is a high-severity ransomware threat attributed to CRPx0, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-2023 · Severity: HIGH · Status: ACTIVE · Category: RANSOMWARE
Attribution: CRPx0 · FINANCIAL
CRPx0, an active double-extortion ransomware-as-a-service operation also tracked as DataBreachPlus, listed Hyundai's Turkish operations (hyundai.com.tr) on its dark-web leak site on 2026-08-01,
CRPx0 is a financially motivated, Python-based ransomware-as-a-service operation first observed in December 2025 and also marketed under the identity DataBreachPlus. Unlike conventional automated ransomware, CRPx0's loader maintains persistent command-and-control (C2) communication and waits for operator instructions before selectively triggering file encryption -- a 'C2-triggered encryption' model that lets affiliates conduct internal reconnaissance and bulk exfiltration before locking systems, maximizing extortion leverage. The malware suite bundles a ransomware/encryption module (crypter.py, Python Fernet-based encryption, appends the .crpx0 extension) with cryptocurrency-theft components: a clipboard hijacker that regex-matches and swaps wallet addresses in real time, and a BIP39 seed-phrase/config-file harvester (finder.py) that also collects browser cookies, Discord tokens, and other stored credentials. Initial access is achieved via social-engineering lures -- disguised as cracked media/OnlyFans archives or counterfeit FedEx shipping notices -- that deliver malicious ZIP archives containing shortcut files invoking the Python interpreter. Cross-platform persistence is established via a Windows HKCU Run key (observed value name 'CryptoGuard') and a scheduled task ('CryptoUpdate', consistent with schtasks.exe abuse) on Windows, and via LaunchAgent property lists (observed: com.sys32.data.plist, com.cryptoprice.guard.plist) on macOS, with working directories such as ~/.sys32data and %APPDATA%\sys32data. CRPx0 operates a RaaS affiliate program offering a 70% cut of extortion proceeds paid within 24 hours in Bitcoin or Monero, supplying affiliates with payload builders and an onion-hosted negotiation dashboard; negotiation and sales channels include Tox and Session messenger identifiers, a Telegram channel (@DataBreachPlus), and a ProtonMail address, alongside a clearnet leak portal (databreach.space) and a separate .su leak-site domain (crpx0.su). In the confirmed incident anchoring this threat, CRPx0 listed Hyundai's Turkish operations (hyundai.com.tr) on its leak site with 'pending' status, claiming roughly 1.5GB of exfiltrated data comprising candidate interview answers and evaluation scores, recruitment-tracking records, proctored-exam photos/videos, executive psychometric/personality assessment reports, and internal recruitment-related email correspondence. The listing had drawn over 3,100 unique views and carried a countdown timer of roughly four days before threatened public release. This listing is not isolated: within the same week CRPx0 added at least 10-11 Turkey-based and multinational victims to its portal -- including Turkish Airlines (4.2GB claimed, recruitment/assessment data), Kuveyt Turk (0.8GB), Anadolu Sigorta, Aselsan, QNB Finansbank/QNB Turkiye, Dogan Holding, Anadolubank, A101, Togg, and Johnson & Johnson -- aggregating a claimed 21.6GB of HR, recruitment, and executive-assessment data marketed as a bundled underground sale on forums such as altenens.is. The consistent targeting of centralized HR/recruitment-assessment portals across otherwise unrelated sectors (automotive, aviation, banking, insurance, defense, retail) suggests either a shared third-party HR/assessment platform vendor or a deliberate campaign focus on recruitment-data aggregators as a high-value, under-defended target class. CRPx0 has separately been linked to prior high-profile automotive-sector activity in threat-intel reporting (distinct from and unrelated to the 2024 Black Basta attack on Hyundai Motor Europe and the 2025 Hyundai AutoEver America SSN/driver's-license breach, neither of which has been attributed to CRPx0).
Target sectors: automotive, aviation, banking, insurance, defense, retail, health, media-and-marketing, consulting, fashion-and-textiles
Target regions: turkey, united states of america, netherlands, sweden, Europe
Timeline
- CRPx0 (DataBreachPlus) ransomware-as-a-service operation first observed/tracked by researchers, per WatchGuard's CRPxO ransomware tracker.
- Early wave of CRPx0 victim notifications concentrated in the US, per WatchGuard tracker data (38 known victims, primarily US with additional Netherlands and Sweden victims).
- Mallory.ai publishes a detailed CRPx0/DataBreachPlus malware profile documenting the Python-based loader, Fernet-encryption ransomware module, clipper/seed-harvester components, IOCs, and MITRE ATT&CK mapping.
- DuoCircle's weekly cybersecurity news roundup reports CRPx0's listing of Hyundai's Turkish operations with 1.5GB of claimed exfiltrated assessment data.
- CRPxO claims a ransomware/data-extortion attack on Kuveyt Turk (Turkish banking sector), publishing 0.8GB of claimed exfiltrated data.
- Anadolu Sigorta (Turkish insurance) is recorded as a CRPxO-claimed victim on Ransomware.live and corroborated by RedPacketSecurity.
- GBHackers reports CRPx0 listed Hyundai's Turkish operations (hyundai.com.tr) on its dark-web leak site with a 'pending' status, claiming ~1.5GB of candidate-assessment/recruitment data, over 3,100 unique leak-site views, and a countdown timer of roughly four days.
- CRPx0 claims a breach of Turkish Airlines (THY), advertising 4.2GB of claimed candidate-record, interview-result, and psychometric-report data; status reported as pending verification.
- FalconFeeds.io publishes an alert identifying that CRPx0 has added multiple Turkey-based/multinational victims to its dark-web portal in the same window: A101, Aselsan, Hyundai, Anadolu Sigorta, Dogan Holding, Johnson & Johnson, Turkish Airlines, Anadolubank, QNB Turkiye, and Kuveyt Turk.
- Brinztech reports CRPxO aggregating claims across 11 major Turkish and multinational enterprises into a single ~21.6GB HR/executive-records sale thread posted to the altenens.is underground forum.
- DarknetSearch publishes an analysis of the CRPx0 Hyundai Turkey leak-site claim, noting the claim remains unverified and describing the group's general double-extortion tactics.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
2 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
RANSOMWARE, HIGH, threat intelligence, cybersecurity, T1566, T1566.002, T1059.006, T1204.002, T1547.001, T1053.005, T1543.001, T1036, T1027.010, T1552.001