Webinar
February 26
Better SOC with Interactive Sandbox
Practical Use Cases
OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.
|
Stealer
Type
:
|
Unknown
Origin
:
|
|
1 April, 2026
First seen
:
|
10 August, 2026
Last seen
:
|
|
Type
:
|
Unknown
Origin
:
|
|
1 April, 2026
First seen
:
|
10 August, 2026
Last seen
:
|
ABRSubProcess.exe to sideload a malicious borlndmm.dll, allowing the threat to bypass traditional antivirus engines.
OnyxC2 analysis inside ANY.RUN’s Interactive Sandbox
Setup_File.zip), preventing automated scanners from inspecting the malicious content.OnyxC2 is a sophisticated Malware-as-a-Service (MaaS) info-stealer and remote access toolkit that first appeared on cybercrime forums in early 2026. It is designed to be a comprehensive, turnkey solution for threat actors, enabling even those with limited technical skills to launch high-volume credential theft and account takeover campaigns. The malware is particularly dangerous because it does not just harvest passwords; it is specifically engineered to collect session material, cookies, and 2FA backup data that allow attackers to bypass multi-factor authentication and maintain access even after a victim resets their password.
A page hosting an OnyxC2 archive
OnyxC2 is highly versatile, with a target list that covers over 200 applications. It targets dozens of Chromium-based and Gecko-based browsers to scrape saved logins and cookies. It specifically hunts for browser-based password managers and two-factor authentication (2FA) extensions, which are critical for bypassing modern security layers. The stealer scrapes data from numerous cryptocurrency wallets, FTP clients, and email clients, pushing the threat beyond consumer-level theft and into the business systems used by finance and operations teams. Beyond credentials, it harvests credit card information, autofill entries, and session tokens.
The malware is delivered via a legitimate application carrying a valid Authenticode signature, which often results in zero detections on platforms like VirusTotal. This signed binary loads a malicious DLL disguised as a legitimate system component, such as an NVIDIA graphics library. The malicious payload remains encrypted until runtime, meaning there is no detectable malicious code on the disk before the execution begins. Payloads are frequently delivered in password-protected ZIP archives to bypass email security gateways that cannot inspect encrypted content.
For a higher subscription price, OnyxC2 evolves from a simple stealer into a modular remote access platform. This "premium" toolkit includes:
OnyxC2 is managed as a professional commercial product, sold through a tiered subscription model on the dark web. The developers provide a centralized administrative dashboard where affiliates can manage "bots," view logs, and use a builder to generate new malware instances.
For modern enterprises, OnyxC2 represents a shift from simple credential harvesting toward complete infrastructure takeover and long-term persistence. By industrializing the theft of session material, this platform creates several critical risks:
The targeting profile of OnyxC2 is broad and opportunistic, designed to exploit the ubiquitous nature of modern web-based work and financial applications:
Detonating an OnyxC2 sample in the ANY.RUN Interactive Sandbox provides a transparent, step-by-step look at how this Malware-as-a-Service operation bypasses traditional security perimeters. By moving beyond static signatures, defenders can observe the following stages of the attack in real-time:
A page hosting an OnyxC2 archive
The infection chain often begins with a victim visiting a phishing URL disguised as a legitimate software download page In the sandbox environment, analysts can observe a series of sequential HTTP redirects through multiple intermediary pages designed to obfuscate the final destination of the malware.
An OnyxC2 complete phishing redirect chain analysis inside ANY.RUN’s Sandbox
A critical evasion tactic occurs during the redirection phase: the presence of "Canvas fingerprinting". The phishing page actively collects characteristics of the victim's browser and execution environment to verify it is a real user rather than an automated security scanner before delivering the malicious payload.
An OnyxC2 payload hidden inside an archive
To bypass email security gateways and automated antivirus analysis, OnyxC2 is frequently delivered as a password-protected ZIP archive (e.g., Setup_File.zip with the password 2026). Because most security tools cannot inspect the encrypted contents of the archive, the malicious files are delivered to the user without prior detection.
Upon extraction, the archive reveals a legitimate-looking executable (e.g., Setup_File_92.118.3096.exe) and a malicious DLL (borlndmm.dll). The executable often carries valid metadata, such as being described as ABRSubProcess.exe from ACCA software S.p.A., to build trust with the victim. When launched, the signed binary utilizes DLL sideloading to silently load the malicious library into memory.
Once the initial execution is successful, the process tree reveals that the malware creates a child instance of itself. This behavior is indicative of the malware unpacking its core payload into the new process, effectively transitioning from the loader stage to the active stealer logic.
ANY.RUN’s Interactive Sandbox detects OnyxC2 fast
With the payload fully deployed, OnyxC2 initiates its primary functions: harvesting credentials, session cookies, and financial data from over 200 targeted applications. If the "premium" build is utilized, the malware also activates advanced remote access features, such as HVNC over a web browser and LSASS memory dumping, granting the operator total control over the compromised workstation.
Because OnyxC2 operates as a Malware-as-a-Service (MaaS) with infrastructure that rotates rapidly, traditional static blocklists are often insufficient for long-term protection. Security teams must shift from tracking temporary indicators to identifying the durable technical fingerprints and behavioral patterns of the operation. By leveraging ANY.RUN’s Threat Intelligence, organizations can stay ahead of these evolving campaigns.
Threat Intelligence Lookup allows analysts to pivot from a single suspicious artifact to an entire cluster of related malicious activity by searching for the "technical DNA" of the malware.
The following TI Lookup query reveals that the malware is linked to attacks on organizations in tech, government, and education from countries like Canada, Israel and the UK.
ANY.RUN’s TI Lookup reveals full threat landscape related to OnyxC2
OnyxC2 consistently uses DLL sideloading, where a legitimate, signed binary (such as ABRSubProcess.exe by ACCA software S.p.A.) is used to load a malicious DLL (like borlndmm.dll). Security teams can use TI Lookup to search for these specific file name combinations or the Authenticode signatures of the legitimate hosts used in the attack chain.
Even when domains change, the underlying assets of the phishing pages, such as the specific scripts used for Canvas fingerprinting to vet victims, remain stable. Analysts can search for these behavioral signatures to identify new phishing URLs before they are widely reported.
For organizations that require automated, high-speed protection, ANY.RUN’s Threat Intelligence Feeds provide a real-time stream of validated indicators. The feeds deliver a continuous flow of the latest C2 domains, IP addresses, and malicious URLs directly into SIEM, SOAR, and EDR platforms. The intel is extracted from the latest malware & phishing investigations of ANY.RUN’s global community of 15K organizations and 600K analysts.
By integrating these feeds, teams can automatically block emerging malicious infrastructure, such as the newly created phishing pages used to harvest credentials. Since OnyxC2 often deploys secondary tools like HVNC or reverse shells, the feeds provide critical network indicators for these remote management protocols, allowing teams to detect active breaches before data exfiltration occurs.
OnyxC2 represents the industrialization of modern cybercrime, providing low-skilled threat actors with a sophisticated platform for large-scale credential theft and account takeover. Its primary danger lies in its move beyond simple password harvesting; by targeting the session cookies and 2FA material that survive a password reset, it grants attackers "standing visibility" into a victim's entire digital working life.
To combat this threat, organizations must move beyond static blocklists and reactive defenses. Because OnyxC2 is sold as a Service (MaaS) with rapidly rotating infrastructure, successful mitigation depends on identifying the durable technical fingerprints. Implementing interactive sandboxing and proactive threat intelligence is essential to deobfuscate encrypted payloads and identify the modular remote access features, such as HVNC, that allow operators to inherit authenticated user sessions outright.
OnyxC2 is a sophisticated Malware-as-a-Service (MaaS) stealer and remote access toolkit that targets browsers, crypto wallets, and business-critical tools like FTP clients. It is sold on a subscription basis, allowing affiliates to deploy high-volume campaigns for a monthly fee.
The malware utilizes DLL sideloading, where a legitimate, signed executable is used to load a malicious DLL disguised as a system library. Because the primary executable carries a valid Authenticode signature, it often results in zero detections by automated security scanners.
The premium tier includes a modular remote access toolkit featuring HVNC (Hidden Virtual Network Computing) and LSASS memory dumping. These features allow an attacker to inherit a victim's authenticated browser session and perform actions in the background without the user's knowledge, bypassing MFA entirely.
Companies must integrate interactive sandboxing and proactive threat intelligence to expose the modular logic that evades traditional scanners. By using tools like TI Lookup and TI Feeds, security teams can identify stable build-chain fingerprints and block rotating infrastructure in real-time.
The stealer scrapes data from Chromium-based and Gecko-based browsers, as well as 2FA extensions and password managers. It specifically targets business systems like email and VPN clients to move beyond consumer theft and into corporate infrastructure.