Huntress has identified a new ransomware variant called Crux, observed across three separate incidents in early July 2025. The threat actors claim affiliation with the BlackByte ransomware-as-a-service group. Encrypted files use the .crux extension and ransom notes reference BlackBCruxSupport@onionmail.org. Initial access in at least one incident was via RDP using valid credentials. The ransomware follows a distinctive process tree: unsigned binary → svchost.exe → cmd.exe → bcdedit.exe, the latter used to disable system recovery. Additional TTPs include remote Registry dumping, driver installation, lateral movement, and data exfiltration via Rclone. Indicators of compromise including file hashes, paths, and a driver file are provided.