Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

OnyxC2

0
Global rank
0
Month rank
0
Week rank
0
IOCs

OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.

Stealer
Type
Unknown
Origin
1 April, 2026
First seen
10 August, 2026
Last seen

How to analyze OnyxC2 with ANY.RUN

Type
Unknown
Origin
1 April, 2026
First seen
10 August, 2026
Last seen

IOCs

Last Seen at

Recent blog posts

post image
Safeguarding 200M Users: How ChongLuaDao Scal...
watchers 6401
comments 0
post image
Major Cyber Attacks in July 2026: US and EU O...
watchers 10462
comments 0
post image
Threat Coverage Digest: New TI Report, Threat...
watchers 16052
comments 0

Key Takeaways

  • Advanced Evasion via DLL Sideloading: Similar to other malware like ValleyRAT and XRed OnyxC2 utilizes legitimate applications with valid Authenticode signatures to load malicious payloads disguised as system libraries (e.g., masked as an NVIDIA graphics library). ANY.RUN analysts observed the use of signed binaries like ABRSubProcess.exe to sideload a malicious borlndmm.dll, allowing the threat to bypass traditional antivirus engines.

OnyxC2 analysis inside ANY.RUN’s Interactive Sandbox OnyxC2 analysis inside ANY.RUN’s Interactive Sandbox

  • Massive Application Targeting: The stealer is engineered to scrape data from over 200 applications, including Chromium-based browsers, crypto wallets, and password managers. By specifically targeting 2FA extensions and session cookies, it allows attackers to bypass multi-factor authentication and maintain access that survives password resets.
  • Modular Remote Access Capabilities: Beyond credential theft, the "premium" tier of OnyxC2 includes a high-risk remote access toolkit featuring HVNC (Hidden Virtual Network Computing), LSASS memory dumping, and reverse shells. This allows operators to inherit authenticated browser sessions and maintain total control over the victim's environment.
  • Strategic Vetting and Delivery: Phishing pages for OnyxC2 employ "Canvas fingerprinting" to profile the victim’s environment before providing the payload. To evade email security gateways, the malware is frequently delivered in password-protected ZIP archives (e.g., Setup_File.zip), preventing automated scanners from inspecting the malicious content.
  • Industrialized MaaS Model: Sold as a subscription, OnyxC2 democratizes sophisticated cybercrime by providing low-skilled affiliates with ready-made lures, a centralized management panel, and a "service guarantee" against detection.

What is OnyxC2?

OnyxC2 is a sophisticated Malware-as-a-Service (MaaS) info-stealer and remote access toolkit that first appeared on cybercrime forums in early 2026. It is designed to be a comprehensive, turnkey solution for threat actors, enabling even those with limited technical skills to launch high-volume credential theft and account takeover campaigns. The malware is particularly dangerous because it does not just harvest passwords; it is specifically engineered to collect session material, cookies, and 2FA backup data that allow attackers to bypass multi-factor authentication and maintain access even after a victim resets their password.

A page hosting an OnyxC2 archive A page hosting an OnyxC2 archive

OnyxC2 is highly versatile, with a target list that covers over 200 applications. It targets dozens of Chromium-based and Gecko-based browsers to scrape saved logins and cookies. It specifically hunts for browser-based password managers and two-factor authentication (2FA) extensions, which are critical for bypassing modern security layers. The stealer scrapes data from numerous cryptocurrency wallets, FTP clients, and email clients, pushing the threat beyond consumer-level theft and into the business systems used by finance and operations teams. Beyond credentials, it harvests credit card information, autofill entries, and session tokens.

The malware is delivered via a legitimate application carrying a valid Authenticode signature, which often results in zero detections on platforms like VirusTotal. This signed binary loads a malicious DLL disguised as a legitimate system component, such as an NVIDIA graphics library. The malicious payload remains encrypted until runtime, meaning there is no detectable malicious code on the disk before the execution begins. Payloads are frequently delivered in password-protected ZIP archives to bypass email security gateways that cannot inspect encrypted content.

For a higher subscription price, OnyxC2 evolves from a simple stealer into a modular remote access platform. This "premium" toolkit includes:

  • HVNC (Hidden Virtual Network Computing): This allows the operator to inherit the victim's authenticated browser sessions outright, performing actions in the background without the user's knowledge.
  • LSASS Memory Dumping: A technique used to extract additional credentials directly from the system memory.
  • Operational Control: The toolkit provides a file manager, keylogger, screenshot capture, reverse SOCKS5 proxy, and a reverse shell over HTTP for total system command.

OnyxC2 is managed as a professional commercial product, sold through a tiered subscription model on the dark web. The developers provide a centralized administrative dashboard where affiliates can manage "bots," view logs, and use a builder to generate new malware instances.

How OnyxC2 Threatens Businesses and Organizations

For modern enterprises, OnyxC2 represents a shift from simple credential harvesting toward complete infrastructure takeover and long-term persistence. By industrializing the theft of session material, this platform creates several critical risks:

  • Bypassing Multi-Factor Authentication (MFA): Unlike traditional stealers that only capture passwords, OnyxC2 is specifically engineered to scrape session cookies and 2FA backup material. This allows attackers to bypass MFA challenges entirely, as the stolen session tokens confirm to the server that the user has already authenticated.
  • Persistent Foothold: OnyxC2 is designed to maintain access across sessions, ensuring that a single compromise yields continuous visibility into the workstation's activities. One successful infection allows threat actors to monitor browsers, password managers, and email sessions in real-time as the victim continues to work.
  • Business System Exposure: The malware targets popular enterprise applications, moving beyond consumer data to focus on business-critical systems like FTP clients, VPN credentials, and email accounts. This places the core systems used by finance and operations teams at immediate risk of compromise.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

The targeting profile of OnyxC2 is broad and opportunistic, designed to exploit the ubiquitous nature of modern web-based work and financial applications:

  • Cryptocurrency and Financial Sectors: The toolkit is heavily optimized for financial theft, targeting different cryptocurrency wallets and numerous password manager extensions.
  • Small and Medium Businesses (SMBs): Phishing lures often masquerade as business software such as "FinePrint" or "SystemSettings," specifically designed to trick office workers and operations teams into running the payload.
  • Global Reach: While the malware appears on global cybercrime forums, its targets are universal; any user with a targeted application installed—ranging from messaging apps and VPNs to note-taking and remote access tools—is a potential victim.
  • Users Bypassing Security Protocols: Organizations that do not use interactive sandboxing to analyze incoming files are particularly vulnerable, as the malware’s DLL sideloading technique often results in zero detections by traditional antivirus engines.

How Does OnyxC2 Malware Function? (The Sandbox Analysis)

Detonating an OnyxC2 sample in the ANY.RUN Interactive Sandbox provides a transparent, step-by-step look at how this Malware-as-a-Service operation bypasses traditional security perimeters. By moving beyond static signatures, defenders can observe the following stages of the attack in real-time:

Stage 1: The Initial Lure and Strategic Redirects

A page hosting an OnyxC2 archive A page hosting an OnyxC2 archive

The infection chain often begins with a victim visiting a phishing URL disguised as a legitimate software download page In the sandbox environment, analysts can observe a series of sequential HTTP redirects through multiple intermediary pages designed to obfuscate the final destination of the malware.

Stage 2: Browser Profiling and Vetting

An OnyxC2 complete phishing page analysis inside ANY.RUN’s Sandbox An OnyxC2 complete phishing redirect chain analysis inside ANY.RUN’s Sandbox

A critical evasion tactic occurs during the redirection phase: the presence of "Canvas fingerprinting". The phishing page actively collects characteristics of the victim's browser and execution environment to verify it is a real user rather than an automated security scanner before delivering the malicious payload.

Stage 3: Protected Archive Delivery

An OnyxC2 payload hidden inside an archive An OnyxC2 payload hidden inside an archive

To bypass email security gateways and automated antivirus analysis, OnyxC2 is frequently delivered as a password-protected ZIP archive (e.g., Setup_File.zip with the password 2026). Because most security tools cannot inspect the encrypted contents of the archive, the malicious files are delivered to the user without prior detection.

Stage 4: Execution through DLL Sideloading

Upon extraction, the archive reveals a legitimate-looking executable (e.g., Setup_File_92.118.3096.exe) and a malicious DLL (borlndmm.dll). The executable often carries valid metadata, such as being described as ABRSubProcess.exe from ACCA software S.p.A., to build trust with the victim. When launched, the signed binary utilizes DLL sideloading to silently load the malicious library into memory.

Stage 5: Payload Deployment and Process Branching

Once the initial execution is successful, the process tree reveals that the malware creates a child instance of itself. This behavior is indicative of the malware unpacking its core payload into the new process, effectively transitioning from the loader stage to the active stealer logic.

ANY.RUN’s Interactive Sandbox detects OnyxC2 fast ANY.RUN’s Interactive Sandbox detects OnyxC2 fast

Stage 6: Data Harvesting and Remote Access

With the payload fully deployed, OnyxC2 initiates its primary functions: harvesting credentials, session cookies, and financial data from over 200 targeted applications. If the "premium" build is utilized, the malware also activates advanced remote access features, such as HVNC over a web browser and LSASS memory dumping, granting the operator total control over the compromised workstation.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against OnyxC2

Because OnyxC2 operates as a Malware-as-a-Service (MaaS) with infrastructure that rotates rapidly, traditional static blocklists are often insufficient for long-term protection. Security teams must shift from tracking temporary indicators to identifying the durable technical fingerprints and behavioral patterns of the operation. By leveraging ANY.RUN’s Threat Intelligence, organizations can stay ahead of these evolving campaigns.

Threat Intelligence Lookup allows analysts to pivot from a single suspicious artifact to an entire cluster of related malicious activity by searching for the "technical DNA" of the malware.

The following TI Lookup query reveals that the malware is linked to attacks on organizations in tech, government, and education from countries like Canada, Israel and the UK.

threatName:"onyxc2"

ANY.RUN’s TI Lookup reveals full threat landscape related to OnyxC2 ANY.RUN’s TI Lookup reveals full threat landscape related to OnyxC2

OnyxC2 consistently uses DLL sideloading, where a legitimate, signed binary (such as ABRSubProcess.exe by ACCA software S.p.A.) is used to load a malicious DLL (like borlndmm.dll). Security teams can use TI Lookup to search for these specific file name combinations or the Authenticode signatures of the legitimate hosts used in the attack chain. Even when domains change, the underlying assets of the phishing pages, such as the specific scripts used for Canvas fingerprinting to vet victims, remain stable. Analysts can search for these behavioral signatures to identify new phishing URLs before they are widely reported.

For organizations that require automated, high-speed protection, ANY.RUN’s Threat Intelligence Feeds provide a real-time stream of validated indicators. The feeds deliver a continuous flow of the latest C2 domains, IP addresses, and malicious URLs directly into SIEM, SOAR, and EDR platforms. The intel is extracted from the latest malware & phishing investigations of ANY.RUN’s global community of 15K organizations and 600K analysts.

By integrating these feeds, teams can automatically block emerging malicious infrastructure, such as the newly created phishing pages used to harvest credentials. Since OnyxC2 often deploys secondary tools like HVNC or reverse shells, the feeds provide critical network indicators for these remote management protocols, allowing teams to detect active breaches before data exfiltration occurs.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

OnyxC2 represents the industrialization of modern cybercrime, providing low-skilled threat actors with a sophisticated platform for large-scale credential theft and account takeover. Its primary danger lies in its move beyond simple password harvesting; by targeting the session cookies and 2FA material that survive a password reset, it grants attackers "standing visibility" into a victim's entire digital working life.

To combat this threat, organizations must move beyond static blocklists and reactive defenses. Because OnyxC2 is sold as a Service (MaaS) with rapidly rotating infrastructure, successful mitigation depends on identifying the durable technical fingerprints. Implementing interactive sandboxing and proactive threat intelligence is essential to deobfuscate encrypted payloads and identify the modular remote access features, such as HVNC, that allow operators to inherit authenticated user sessions outright.

Frequently Asked Questions: OnyxC2

1. What is OnyxC2?

OnyxC2 is a sophisticated Malware-as-a-Service (MaaS) stealer and remote access toolkit that targets browsers, crypto wallets, and business-critical tools like FTP clients. It is sold on a subscription basis, allowing affiliates to deploy high-volume campaigns for a monthly fee.

2. How does OnyxC2 bypass traditional antivirus software?

The malware utilizes DLL sideloading, where a legitimate, signed executable is used to load a malicious DLL disguised as a system library. Because the primary executable carries a valid Authenticode signature, it often results in zero detections by automated security scanners.

3. Why is the "premium" version of OnyxC2 particularly dangerous for businesses?

The premium tier includes a modular remote access toolkit featuring HVNC (Hidden Virtual Network Computing) and LSASS memory dumping. These features allow an attacker to inherit a victim's authenticated browser session and perform actions in the background without the user's knowledge, bypassing MFA entirely.

4. How can organizations mitigate this threat?

Companies must integrate interactive sandboxing and proactive threat intelligence to expose the modular logic that evades traditional scanners. By using tools like TI Lookup and TI Feeds, security teams can identify stable build-chain fingerprints and block rotating infrastructure in real-time.

5. What types of applications does OnyxC2 target?

The stealer scrapes data from Chromium-based and Gecko-based browsers, as well as 2FA extensions and password managers. It specifically targets business systems like email and VPN clients to move beyond consumer theft and into corporate infrastructure.

HAVE A LOOK AT

Ransomware screenshot
Ransomware
ransomware
Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.
Read More
UpCrypter screenshot
UpCrypter
upcrypter
UpCrypter is a sophisticated malware loader that functions as a delivery mechanism for remote access tools. Distributed through global phishing campaigns targeting Windows systems, this actively maintained tool serves as the central framework for deploying various RATs including PureHVNC, DCRat, and Babylon RAT, enabling attackers to establish persistent remote control over compromised systems.
Read More
Wshrat screenshot
Wshrat
wshrat rat trojan
WSHRAT is a Remote Access Trojan — a malware that allows the attackers to take over the infected machines. The RAT has been in circulation since 2013 and it is arguably most notable for the numerous versions released into the wild.
Read More
Kali365 screenshot
Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform that targets Microsoft 365 environments by stealing OAuth authentication tokens instead of passwords. First observed in April 2026, the service enables even low-skilled threat actors to bypass multi-factor authentication (MFA), gain persistent access to corporate cloud accounts, and compromise business communications, files, and collaboration platforms. Kali365 represents a shift from traditional credential theft toward session hijacking and token abuse, making it a significant threat to organizations that rely on Microsoft 365.
Read More
Netwalker screenshot
Netwalker
netwalker ransomware
Netwalker is ransomware — it belongs to a malware family which encrypts files and demands users to pay a ransom to get their data back. Netwalker utilizes several sophisticated techniques, such as process hollowing and code obfuscation to target corporate victims.
Read More
Kratos screenshot
Kratos
kratos
Kratos is a mature Phishing-as-a-Service (PhaaS) platform that evolved from the Sneaky2FA kit to specialize in stealing Microsoft 365 credentials through sophisticated Adversary-in-the-Middle (AiTM) techniques. The service provides low-skilled affiliates with a turnkey solution featuring an advanced administrative dashboard, integrated anti-bot defenses, and real-time data exfiltration via the Telegram Bot API. Although an international law enforcement action known as Operation Olympus Blade disrupted its central infrastructure in July 2026, the kit remains a primary example of the industrialization of modern cybercrime.
Read More