Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

OnyxC2

131
Global rank
84 infographic chevron month
Month rank
80 infographic chevron week
Week rank

OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.

Stealer
Type
Unknown
Origin
1 April, 2026
First seen
7 October, 2026
Last seen

How to analyze OnyxC2 with ANY.RUN

Type
Unknown
Origin
1 April, 2026
First seen
7 October, 2026
Last seen

IOCs

IP addresses
109.195.177.157
1.52.220.121
139.175.68.142
64.76.25.127
192.81.131.190
162.159.46.1
1.1.141.102
54.209.71.248
12.185.61.49
121.78.147.191
193.218.36.234
172.64.37.216
172.64.37.218
192.227.194.176
1.4.200.68
1.4.203.157
71.58.205.31
202.78.224.129
8.26.226.30
174.46.108.47
Hashes
f1b3e0f2750a9103e46a6a4a34f1cf9d17779725f98042cc2475ec66484801cf
02bdde38e4c6bd795a092d496b8d6060cdbe71e22ef4d7a204e3050c1be44fa9
2026f3c4f830dff6883b88e2647272a52a132f25eb42c0d423e36b3f65a94d08
388a796580234efc95f3b1c70ad4cb44bfddc7ba0f9203bf4902b9929b136f95
d736c413543b6b168dc59769840ae95b5726d428f69a23af1659dea8fb4236c8
31d04c1e4bfdfa34704c142fa98f80c0a3076e4b312d6ada57c4be9d9c7dcf26
e63e7ebe4c2db7e61ffc71af0675e870bcde0a9d8916e5b3be0cb252478030bf
f1332dc08bb3249461551d22d74ba8c52e6bf6a6540c39c2377a1f6471584d9a
d1111b245f685176180e6f1631e6dc49badf6672368e9ce260c71355165effdf
3715d1887922bdfaa3b0bbca44bb748417f4c6ed7ae1684bf6a8a1a60398bef6
e6b7e7eda14ccbf350840ea3101d0e2122103ba0897c7f0de5a8ab9347678340
b8c4439ddcccb2400cd50e1ebb62d57b8a32b3b4570043d63869d1a8ed350afd
049b268f6fe7dee81651ff0d3ddc72b205f465c9aba3e57e9222fe9c5eadff88
6742df2aedbcc735ea27210f7e6bcd9f4f648e7f66d1c1ad01a49396235bec29
0f9bc66562907ab86412e7f375596e93449b40836b12343d6d6aae82d0e7d72f
b8b8f81aa24c1679d98e1c47691b97e602a7b56c4c398cbd7e4a5347f053e701
7d46b869f4cedd631c359629581cf0e86dfbbf92622c21e91e2a4b4a4e8036a3
f9f204c544cb4d54fa0f4a42459d68a2618699a29486ef7f63396161ac17fbea
937f694dc3a750c12bbc3951b9fe18f8665be1469178d177d3ede1c95ab8883f
b9f9c58e080f1b5028e8e331fdc0aa5d5c43646d747031615d4645800fe87a02
Domains
slscr.update.microsoft.com
dns.google
settings-win.data.microsoft.com
google.com
activation-v2.sls.microsoft.com
login.live.com
drive.usercontent.google.com
th.bing.com
cloudflare-dns.com
www.bing.com
fe3cr.delivery.mp.microsoft.com
www.microsoft.com
crl.microsoft.com
self.events.data.microsoft.com
lean.brilliancespontaneous.shop
ocsp.digicert.com
ecs.office.com
public-dns.info
nexusrules.officeapps.live.com
simplswop.io
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaafuwohyjguzpcaaaaaaau%3d
http://c.pki.goog/we2/yk5nphthkqs.crl
https://drive.usercontent.google.com/download?id=1ybvidkzgygnfuu2rbjxxcydrzay5rmdy&export=download&authuser=0&confirm=t
http://91.92.242.236/dll
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://th.bing.com/th?id=odswg.iotdlocalicon&w=16&h=16&c=1&rs=1&p=0
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
http://91.92.242.236/update
http://91.92.242.236/service
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://c.pki.goog/we1/p3mludmhroi.crl
https://simplswop.io/backend/api/app.php?action=sync&hwid=1fb83ad2fdd479f062154b3aec794d5f&tag=44&username=admin&osversion=windows+10+%28build+19045%29&privileges=user&antivirusname=windows+defender&cpuname=amd+ryzen+5+3500+6-core+processor&gpuname=nvidia+geforce+gt+730&botversion=7.0&exepath=c%3a%5cprogramdata%5cedgeupdate%5cmicrosoftedgesecurity.exe&ownertoken=0e83407fa297ad910659352a3823db716e3342599b1eac2da542245721920778
https://simplswop.io/backend/api/app.php?action=poll&hwid=1fb83ad2fdd479f062154b3aec794d5f&topwindowname=debug&userpcstatus=active&botversion=7.0
Last Seen at
Last Seen at

Recent blog posts

post image
Making Threat Intelligence Work for SOC Teams...
watchers 6051
comments 0
post image
5 Critical Pain Points of Modern US SOCs and...
watchers 7861
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 11489
comments 0

Key Takeaways

  • Advanced Evasion via DLL Sideloading: Similar to other malware like ValleyRAT and XRed OnyxC2 utilizes legitimate applications with valid Authenticode signatures to load malicious payloads disguised as system libraries (e.g., masked as an NVIDIA graphics library). ANY.RUN analysts observed the use of signed binaries like ABRSubProcess.exe to sideload a malicious borlndmm.dll, allowing the threat to bypass traditional antivirus engines.

OnyxC2 analysis inside ANY.RUN’s Interactive Sandbox OnyxC2 analysis inside ANY.RUN’s Interactive Sandbox

  • Massive Application Targeting: The stealer is engineered to scrape data from over 200 applications, including Chromium-based browsers, crypto wallets, and password managers. By specifically targeting 2FA extensions and session cookies, it allows attackers to bypass multi-factor authentication and maintain access that survives password resets.
  • Modular Remote Access Capabilities: Beyond credential theft, the "premium" tier of OnyxC2 includes a high-risk remote access toolkit featuring HVNC (Hidden Virtual Network Computing), LSASS memory dumping, and reverse shells. This allows operators to inherit authenticated browser sessions and maintain total control over the victim's environment.
  • Strategic Vetting and Delivery: Phishing pages for OnyxC2 employ "Canvas fingerprinting" to profile the victim’s environment before providing the payload. To evade email security gateways, the malware is frequently delivered in password-protected ZIP archives (e.g., Setup_File.zip), preventing automated scanners from inspecting the malicious content.
  • Industrialized MaaS Model: Sold as a subscription, OnyxC2 democratizes sophisticated cybercrime by providing low-skilled affiliates with ready-made lures, a centralized management panel, and a "service guarantee" against detection.

What is OnyxC2?

OnyxC2 is a sophisticated Malware-as-a-Service (MaaS) info-stealer and remote access toolkit that first appeared on cybercrime forums in early 2026. It is designed to be a comprehensive, turnkey solution for threat actors, enabling even those with limited technical skills to launch high-volume credential theft and account takeover campaigns. The malware is particularly dangerous because it does not just harvest passwords; it is specifically engineered to collect session material, cookies, and 2FA backup data that allow attackers to bypass multi-factor authentication and maintain access even after a victim resets their password.

A page hosting an OnyxC2 archive A page hosting an OnyxC2 archive

OnyxC2 is highly versatile, with a target list that covers over 200 applications. It targets dozens of Chromium-based and Gecko-based browsers to scrape saved logins and cookies. It specifically hunts for browser-based password managers and two-factor authentication (2FA) extensions, which are critical for bypassing modern security layers. The stealer scrapes data from numerous cryptocurrency wallets, FTP clients, and email clients, pushing the threat beyond consumer-level theft and into the business systems used by finance and operations teams. Beyond credentials, it harvests credit card information, autofill entries, and session tokens.

The malware is delivered via a legitimate application carrying a valid Authenticode signature, which often results in zero detections on platforms like VirusTotal. This signed binary loads a malicious DLL disguised as a legitimate system component, such as an NVIDIA graphics library. The malicious payload remains encrypted until runtime, meaning there is no detectable malicious code on the disk before the execution begins. Payloads are frequently delivered in password-protected ZIP archives to bypass email security gateways that cannot inspect encrypted content.

For a higher subscription price, OnyxC2 evolves from a simple stealer into a modular remote access platform. This "premium" toolkit includes:

  • HVNC (Hidden Virtual Network Computing): This allows the operator to inherit the victim's authenticated browser sessions outright, performing actions in the background without the user's knowledge.
  • LSASS Memory Dumping: A technique used to extract additional credentials directly from the system memory.
  • Operational Control: The toolkit provides a file manager, keylogger, screenshot capture, reverse SOCKS5 proxy, and a reverse shell over HTTP for total system command.

OnyxC2 is managed as a professional commercial product, sold through a tiered subscription model on the dark web. The developers provide a centralized administrative dashboard where affiliates can manage "bots," view logs, and use a builder to generate new malware instances.

How OnyxC2 Threatens Businesses and Organizations

For modern enterprises, OnyxC2 represents a shift from simple credential harvesting toward complete infrastructure takeover and long-term persistence. By industrializing the theft of session material, this platform creates several critical risks:

  • Bypassing Multi-Factor Authentication (MFA): Unlike traditional stealers that only capture passwords, OnyxC2 is specifically engineered to scrape session cookies and 2FA backup material. This allows attackers to bypass MFA challenges entirely, as the stolen session tokens confirm to the server that the user has already authenticated.
  • Persistent Foothold: OnyxC2 is designed to maintain access across sessions, ensuring that a single compromise yields continuous visibility into the workstation's activities. One successful infection allows threat actors to monitor browsers, password managers, and email sessions in real-time as the victim continues to work.
  • Business System Exposure: The malware targets popular enterprise applications, moving beyond consumer data to focus on business-critical systems like FTP clients, VPN credentials, and email accounts. This places the core systems used by finance and operations teams at immediate risk of compromise.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

The targeting profile of OnyxC2 is broad and opportunistic, designed to exploit the ubiquitous nature of modern web-based work and financial applications:

  • Cryptocurrency and Financial Sectors: The toolkit is heavily optimized for financial theft, targeting different cryptocurrency wallets and numerous password manager extensions.
  • Small and Medium Businesses (SMBs): Phishing lures often masquerade as business software such as "FinePrint" or "SystemSettings," specifically designed to trick office workers and operations teams into running the payload.
  • Global Reach: While the malware appears on global cybercrime forums, its targets are universal; any user with a targeted application installed—ranging from messaging apps and VPNs to note-taking and remote access tools—is a potential victim.
  • Users Bypassing Security Protocols: Organizations that do not use interactive sandboxing to analyze incoming files are particularly vulnerable, as the malware’s DLL sideloading technique often results in zero detections by traditional antivirus engines.

How Does OnyxC2 Malware Function? (The Sandbox Analysis)

Detonating an OnyxC2 sample in the ANY.RUN Interactive Sandbox provides a transparent, step-by-step look at how this Malware-as-a-Service operation bypasses traditional security perimeters. By moving beyond static signatures, defenders can observe the following stages of the attack in real-time:

Stage 1: The Initial Lure and Strategic Redirects

A page hosting an OnyxC2 archive A page hosting an OnyxC2 archive

The infection chain often begins with a victim visiting a phishing URL disguised as a legitimate software download page In the sandbox environment, analysts can observe a series of sequential HTTP redirects through multiple intermediary pages designed to obfuscate the final destination of the malware.

Stage 2: Browser Profiling and Vetting

An OnyxC2 complete phishing page analysis inside ANY.RUN’s Sandbox An OnyxC2 complete phishing redirect chain analysis inside ANY.RUN’s Sandbox

A critical evasion tactic occurs during the redirection phase: the presence of "Canvas fingerprinting". The phishing page actively collects characteristics of the victim's browser and execution environment to verify it is a real user rather than an automated security scanner before delivering the malicious payload.

Stage 3: Protected Archive Delivery

An OnyxC2 payload hidden inside an archive An OnyxC2 payload hidden inside an archive

To bypass email security gateways and automated antivirus analysis, OnyxC2 is frequently delivered as a password-protected ZIP archive (e.g., Setup_File.zip with the password 2026). Because most security tools cannot inspect the encrypted contents of the archive, the malicious files are delivered to the user without prior detection.

Stage 4: Execution through DLL Sideloading

Upon extraction, the archive reveals a legitimate-looking executable (e.g., Setup_File_92.118.3096.exe) and a malicious DLL (borlndmm.dll). The executable often carries valid metadata, such as being described as ABRSubProcess.exe from ACCA software S.p.A., to build trust with the victim. When launched, the signed binary utilizes DLL sideloading to silently load the malicious library into memory.

Stage 5: Payload Deployment and Process Branching

Once the initial execution is successful, the process tree reveals that the malware creates a child instance of itself. This behavior is indicative of the malware unpacking its core payload into the new process, effectively transitioning from the loader stage to the active stealer logic.

ANY.RUN’s Interactive Sandbox detects OnyxC2 fast ANY.RUN’s Interactive Sandbox detects OnyxC2 fast

Stage 6: Data Harvesting and Remote Access

With the payload fully deployed, OnyxC2 initiates its primary functions: harvesting credentials, session cookies, and financial data from over 200 targeted applications. If the "premium" build is utilized, the malware also activates advanced remote access features, such as HVNC over a web browser and LSASS memory dumping, granting the operator total control over the compromised workstation.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against OnyxC2

Because OnyxC2 operates as a Malware-as-a-Service (MaaS) with infrastructure that rotates rapidly, traditional static blocklists are often insufficient for long-term protection. Security teams must shift from tracking temporary indicators to identifying the durable technical fingerprints and behavioral patterns of the operation. By leveraging ANY.RUN’s Threat Intelligence, organizations can stay ahead of these evolving campaigns.

Threat Intelligence Lookup allows analysts to pivot from a single suspicious artifact to an entire cluster of related malicious activity by searching for the "technical DNA" of the malware.

The following TI Lookup query reveals that the malware is linked to attacks on organizations in tech, government, and education from countries like Canada, Israel and the UK.

threatName:"onyxc2"

ANY.RUN’s TI Lookup reveals full threat landscape related to OnyxC2 ANY.RUN’s TI Lookup reveals full threat landscape related to OnyxC2

OnyxC2 consistently uses DLL sideloading, where a legitimate, signed binary (such as ABRSubProcess.exe by ACCA software S.p.A.) is used to load a malicious DLL (like borlndmm.dll). Security teams can use TI Lookup to search for these specific file name combinations or the Authenticode signatures of the legitimate hosts used in the attack chain. Even when domains change, the underlying assets of the phishing pages, such as the specific scripts used for Canvas fingerprinting to vet victims, remain stable. Analysts can search for these behavioral signatures to identify new phishing URLs before they are widely reported.

For organizations that require automated, high-speed protection, ANY.RUN’s Threat Intelligence Feeds provide a real-time stream of validated indicators. The feeds deliver a continuous flow of the latest C2 domains, IP addresses, and malicious URLs directly into SIEM, SOAR, and EDR platforms. The intel is extracted from the latest malware & phishing investigations of ANY.RUN’s global community of 15K organizations and 600K analysts.

By integrating these feeds, teams can automatically block emerging malicious infrastructure, such as the newly created phishing pages used to harvest credentials. Since OnyxC2 often deploys secondary tools like HVNC or reverse shells, the feeds provide critical network indicators for these remote management protocols, allowing teams to detect active breaches before data exfiltration occurs.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

OnyxC2 represents the industrialization of modern cybercrime, providing low-skilled threat actors with a sophisticated platform for large-scale credential theft and account takeover. Its primary danger lies in its move beyond simple password harvesting; by targeting the session cookies and 2FA material that survive a password reset, it grants attackers "standing visibility" into a victim's entire digital working life.

To combat this threat, organizations must move beyond static blocklists and reactive defenses. Because OnyxC2 is sold as a Service (MaaS) with rapidly rotating infrastructure, successful mitigation depends on identifying the durable technical fingerprints. Implementing interactive sandboxing and proactive threat intelligence is essential to deobfuscate encrypted payloads and identify the modular remote access features, such as HVNC, that allow operators to inherit authenticated user sessions outright.

Frequently Asked Questions: OnyxC2

1. What is OnyxC2?

OnyxC2 is a sophisticated Malware-as-a-Service (MaaS) stealer and remote access toolkit that targets browsers, crypto wallets, and business-critical tools like FTP clients. It is sold on a subscription basis, allowing affiliates to deploy high-volume campaigns for a monthly fee.

2. How does OnyxC2 bypass traditional antivirus software?

The malware utilizes DLL sideloading, where a legitimate, signed executable is used to load a malicious DLL disguised as a system library. Because the primary executable carries a valid Authenticode signature, it often results in zero detections by automated security scanners.

3. Why is the "premium" version of OnyxC2 particularly dangerous for businesses?

The premium tier includes a modular remote access toolkit featuring HVNC (Hidden Virtual Network Computing) and LSASS memory dumping. These features allow an attacker to inherit a victim's authenticated browser session and perform actions in the background without the user's knowledge, bypassing MFA entirely.

4. How can organizations mitigate this threat?

Companies must integrate interactive sandboxing and proactive threat intelligence to expose the modular logic that evades traditional scanners. By using tools like TI Lookup and TI Feeds, security teams can identify stable build-chain fingerprints and block rotating infrastructure in real-time.

5. What types of applications does OnyxC2 target?

The stealer scrapes data from Chromium-based and Gecko-based browsers, as well as 2FA extensions and password managers. It specifically targets business systems like email and VPN clients to move beyond consumer theft and into corporate infrastructure.

HAVE A LOOK AT

Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More
Sliver screenshot
Sliver
sliver
Sliver is an open-source command-and-control (C2) framework that has been increasingly adopted by threat actors as an alternative to tools like Cobalt Strike. Developed by security firm Bishop Fox, Sliver was initially intended for legitimate security testing and red teaming exercises. However, its robust features and open-source nature have made it attractive to malicious actors seeking to control compromised systems.
Read More
SnappyClient screenshot
SnappyClient is a sophisticated C++-based command-and-control (C2) implant first identified in December 2025. Delivered primarily via the modular HijackLoader, it functions as a versatile remote access tool with strong information-stealing capabilities, particularly focused on cryptocurrency wallets, browser data, and system control. It employs advanced evasion techniques, encrypted communications, and modular configurations to maintain persistence and evade detection.
Read More
Virlock screenshot
Virlock
virlock
Virlock is a unique ransomware strain that combines encryption capabilities with file infection techniques. First observed in 2014, it stands out due to its polymorphic nature and ability to embed its code into compromised files, ensuring continued propagation. Once it infects a system, it encrypts files and locks the screen, demanding a ransom for file recovery and system access.
Read More
Oblivion RAT screenshot
Oblivion RAT
oblivion
Oblivion RAT is a sophisticated Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on cybercrime forums for as little as $300 per month. It equips even novice attackers with a complete toolkit, including a web-based APK builder, dropper generator mimicking Google Play updates, and a real-time C2 panel. The RAT enables full device takeover, data theft, and financial fraud through deceptive social engineering and Accessibility Service abuse.
Read More
Mispadu screenshot
Mispadu is a Windows banking trojan known for targeting online banking credentials, cryptocurrency wallets, and sensitive financial information. First identified in Latin America, the malware has continuously evolved with improved evasion techniques, phishing campaigns, and credential theft capabilities. Its reliance on social engineering rather than software vulnerabilities makes it an enduring threat to organizations whose employees interact with financial services online.
Read More