Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

OnyxC2

156
Global rank
152 infographic chevron month
Month rank
199 infographic chevron week
Week rank
0
IOCs

OnyxC2 is a sophisticated Malware-as-a-Service platform sold on cybercrime forums that provides a turnkey solution for high-volume credential theft. The malware targets over 200 applications, scraping sensitive data from browsers, cryptocurrency wallets, and business-critical tools like FTP and email clients. It employs advanced evasion techniques, such as DLL sideloading and browser fingerprinting, to deliver encrypted payloads through legitimate signed binaries.

Stealer
Type
Unknown
Origin
1 April, 2026
First seen
16 August, 2026
Last seen

How to analyze OnyxC2 with ANY.RUN

Type
Unknown
Origin
1 April, 2026
First seen
16 August, 2026
Last seen

IOCs

IP addresses
88.221.169.205
135.233.95.144
48.192.1.64
48.209.138.189
74.178.240.51
40.126.32.136
2.21.20.137
48.209.133.15
172.211.123.248
88.221.169.152
92.122.215.75
104.18.21.213
48.209.6.48
23.209.209.135
57.153.246.3
188.114.97.3
88.221.169.173
23.11.41.157
72.246.29.11
188.114.96.3
Hashes
c2ed69b4a1bb9432c75134e813c70539e27c8c1fe96a784d9be78c874e93d9d5
def46aa6a8f72f27bafac0c43334419486a4d1dcdb6c479a8ef7034b3e1fa4cb
e6bfb3662ab4b1969a73441dbe35c96d51441b6bff8cf1fe7430bd5b246ca605
3715d1887922bdfaa3b0bbca44bb748417f4c6ed7ae1684bf6a8a1a60398bef6
12fd0590708bb38d8039bc994178acee8a3d220f0cd194b0f1c2fc9ba622f927
251ed08cc8f5873098ea5ee083034e7cd99ece955920e12a42e50306a94cb6eb
1e75fd701998008590a79fb60f57c6111ff3c6a3a23b584f061df96f17cdf6ff
a6d4ab7748d54a0cd1ead4abcf279e33ed37c2f98118c3257965c66d546eb046
f937d5907052658a4e50394852c5307392a5eefa9d260fb2d3444d06daf97e90
184146852727a9db4eea06178716bec3cdbb1015c911f6b0f915b184ad7775b2
ac05470242cceb8491ea40eeca387c56926d288e5304939b0d246dac9b9fea84
3dd5ea8a14eb665ba6057d424f94e5e83757ffaab456578dbf038af04053b19e
87e8d39db624f37d3e77aedf487a2dfd197f71a4730ea74f4e7a4341deaec2ff
4e17b44dd227ec7e77b3b4b3392f211e2f79a54db1b9521dc8a1719012682fed
f62c9f677d4613d4a7852740400fad364b19be119453b63091c3245a16cf84ba
9f26a852911a56842bd882fc2cfc7792176e61bf1eb65ff4d2bfcd05bc24592c
8e353373c1ef122a166b0a6205217c4a0f16178d2894e608113637aea2d26ada
2f8951bce256a3fa34e14e532da3e0822a68c247d96ec335174e3d3f2d11ec5a
f76ffa05cb94e78a7c598278ec76ed671ff4783919e31a3330f1ed4c4cc54d20
55cdefe4c84938a888dfe5296a2fefb0e079cd68fd65ff0129f835d7dc94eba4
Domains
ye2.c.lencr.org
akmuniverstall.top
settings-win.data.microsoft.com
google.com
activation-v2.sls.microsoft.com
login.live.com
fe3cr.delivery.mp.microsoft.com
slscr.update.microsoft.com
go.microsoft.com
ye.c.lencr.org
www.microsoft.com
ocsp.digicert.com
x1.c.lencr.org
crl.microsoft.com
client.wns.windows.com
x2.c.lencr.org
self.events.data.microsoft.com
nexusrules.officeapps.live.com
encrypted-tbn0.gstatic.com
normandy.cdn.mozilla.net
URLs
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://settings-win.data.microsoft.com/settings/v3.0/waas/featuremanagement?isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&currentbranch=vb_release&accountfirstchar=&activationchannel=retail&oemmodel=dell&flightring=retail&attrdataver=186&installlanguage=en-us&osuilocale=en-us&webexperience=1&flightingbranchname=&chassistypeid=1&osskuid=48&app=cdm&installdate=1661339444&appver=&osarchitecture=amd64&defaultuserregion=244&telemetrylevel=1&osversion=10.0.19045.4046&devicefamily=windows.desktop
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
https://slscr.update.microsoft.com/sls/%7be7a50285-d08d-499d-9ff8-180fdc2332bc%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
http://x1.c.lencr.org/
http://x2.c.lencr.org/
http://ye.c.lencr.org/
http://ye2.c.lencr.org/25.crl
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 4570
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 10731
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 13129
comments 0

Key Takeaways

  • Advanced Evasion via DLL Sideloading: Similar to other malware like ValleyRAT and XRed OnyxC2 utilizes legitimate applications with valid Authenticode signatures to load malicious payloads disguised as system libraries (e.g., masked as an NVIDIA graphics library). ANY.RUN analysts observed the use of signed binaries like ABRSubProcess.exe to sideload a malicious borlndmm.dll, allowing the threat to bypass traditional antivirus engines.

OnyxC2 analysis inside ANY.RUN’s Interactive Sandbox OnyxC2 analysis inside ANY.RUN’s Interactive Sandbox

  • Massive Application Targeting: The stealer is engineered to scrape data from over 200 applications, including Chromium-based browsers, crypto wallets, and password managers. By specifically targeting 2FA extensions and session cookies, it allows attackers to bypass multi-factor authentication and maintain access that survives password resets.
  • Modular Remote Access Capabilities: Beyond credential theft, the "premium" tier of OnyxC2 includes a high-risk remote access toolkit featuring HVNC (Hidden Virtual Network Computing), LSASS memory dumping, and reverse shells. This allows operators to inherit authenticated browser sessions and maintain total control over the victim's environment.
  • Strategic Vetting and Delivery: Phishing pages for OnyxC2 employ "Canvas fingerprinting" to profile the victim’s environment before providing the payload. To evade email security gateways, the malware is frequently delivered in password-protected ZIP archives (e.g., Setup_File.zip), preventing automated scanners from inspecting the malicious content.
  • Industrialized MaaS Model: Sold as a subscription, OnyxC2 democratizes sophisticated cybercrime by providing low-skilled affiliates with ready-made lures, a centralized management panel, and a "service guarantee" against detection.

What is OnyxC2?

OnyxC2 is a sophisticated Malware-as-a-Service (MaaS) info-stealer and remote access toolkit that first appeared on cybercrime forums in early 2026. It is designed to be a comprehensive, turnkey solution for threat actors, enabling even those with limited technical skills to launch high-volume credential theft and account takeover campaigns. The malware is particularly dangerous because it does not just harvest passwords; it is specifically engineered to collect session material, cookies, and 2FA backup data that allow attackers to bypass multi-factor authentication and maintain access even after a victim resets their password.

A page hosting an OnyxC2 archive A page hosting an OnyxC2 archive

OnyxC2 is highly versatile, with a target list that covers over 200 applications. It targets dozens of Chromium-based and Gecko-based browsers to scrape saved logins and cookies. It specifically hunts for browser-based password managers and two-factor authentication (2FA) extensions, which are critical for bypassing modern security layers. The stealer scrapes data from numerous cryptocurrency wallets, FTP clients, and email clients, pushing the threat beyond consumer-level theft and into the business systems used by finance and operations teams. Beyond credentials, it harvests credit card information, autofill entries, and session tokens.

The malware is delivered via a legitimate application carrying a valid Authenticode signature, which often results in zero detections on platforms like VirusTotal. This signed binary loads a malicious DLL disguised as a legitimate system component, such as an NVIDIA graphics library. The malicious payload remains encrypted until runtime, meaning there is no detectable malicious code on the disk before the execution begins. Payloads are frequently delivered in password-protected ZIP archives to bypass email security gateways that cannot inspect encrypted content.

For a higher subscription price, OnyxC2 evolves from a simple stealer into a modular remote access platform. This "premium" toolkit includes:

  • HVNC (Hidden Virtual Network Computing): This allows the operator to inherit the victim's authenticated browser sessions outright, performing actions in the background without the user's knowledge.
  • LSASS Memory Dumping: A technique used to extract additional credentials directly from the system memory.
  • Operational Control: The toolkit provides a file manager, keylogger, screenshot capture, reverse SOCKS5 proxy, and a reverse shell over HTTP for total system command.

OnyxC2 is managed as a professional commercial product, sold through a tiered subscription model on the dark web. The developers provide a centralized administrative dashboard where affiliates can manage "bots," view logs, and use a builder to generate new malware instances.

How OnyxC2 Threatens Businesses and Organizations

For modern enterprises, OnyxC2 represents a shift from simple credential harvesting toward complete infrastructure takeover and long-term persistence. By industrializing the theft of session material, this platform creates several critical risks:

  • Bypassing Multi-Factor Authentication (MFA): Unlike traditional stealers that only capture passwords, OnyxC2 is specifically engineered to scrape session cookies and 2FA backup material. This allows attackers to bypass MFA challenges entirely, as the stolen session tokens confirm to the server that the user has already authenticated.
  • Persistent Foothold: OnyxC2 is designed to maintain access across sessions, ensuring that a single compromise yields continuous visibility into the workstation's activities. One successful infection allows threat actors to monitor browsers, password managers, and email sessions in real-time as the victim continues to work.
  • Business System Exposure: The malware targets popular enterprise applications, moving beyond consumer data to focus on business-critical systems like FTP clients, VPN credentials, and email accounts. This places the core systems used by finance and operations teams at immediate risk of compromise.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Victimology: Who Is Most Vulnerable?

The targeting profile of OnyxC2 is broad and opportunistic, designed to exploit the ubiquitous nature of modern web-based work and financial applications:

  • Cryptocurrency and Financial Sectors: The toolkit is heavily optimized for financial theft, targeting different cryptocurrency wallets and numerous password manager extensions.
  • Small and Medium Businesses (SMBs): Phishing lures often masquerade as business software such as "FinePrint" or "SystemSettings," specifically designed to trick office workers and operations teams into running the payload.
  • Global Reach: While the malware appears on global cybercrime forums, its targets are universal; any user with a targeted application installed—ranging from messaging apps and VPNs to note-taking and remote access tools—is a potential victim.
  • Users Bypassing Security Protocols: Organizations that do not use interactive sandboxing to analyze incoming files are particularly vulnerable, as the malware’s DLL sideloading technique often results in zero detections by traditional antivirus engines.

How Does OnyxC2 Malware Function? (The Sandbox Analysis)

Detonating an OnyxC2 sample in the ANY.RUN Interactive Sandbox provides a transparent, step-by-step look at how this Malware-as-a-Service operation bypasses traditional security perimeters. By moving beyond static signatures, defenders can observe the following stages of the attack in real-time:

Stage 1: The Initial Lure and Strategic Redirects

A page hosting an OnyxC2 archive A page hosting an OnyxC2 archive

The infection chain often begins with a victim visiting a phishing URL disguised as a legitimate software download page In the sandbox environment, analysts can observe a series of sequential HTTP redirects through multiple intermediary pages designed to obfuscate the final destination of the malware.

Stage 2: Browser Profiling and Vetting

An OnyxC2 complete phishing page analysis inside ANY.RUN’s Sandbox An OnyxC2 complete phishing redirect chain analysis inside ANY.RUN’s Sandbox

A critical evasion tactic occurs during the redirection phase: the presence of "Canvas fingerprinting". The phishing page actively collects characteristics of the victim's browser and execution environment to verify it is a real user rather than an automated security scanner before delivering the malicious payload.

Stage 3: Protected Archive Delivery

An OnyxC2 payload hidden inside an archive An OnyxC2 payload hidden inside an archive

To bypass email security gateways and automated antivirus analysis, OnyxC2 is frequently delivered as a password-protected ZIP archive (e.g., Setup_File.zip with the password 2026). Because most security tools cannot inspect the encrypted contents of the archive, the malicious files are delivered to the user without prior detection.

Stage 4: Execution through DLL Sideloading

Upon extraction, the archive reveals a legitimate-looking executable (e.g., Setup_File_92.118.3096.exe) and a malicious DLL (borlndmm.dll). The executable often carries valid metadata, such as being described as ABRSubProcess.exe from ACCA software S.p.A., to build trust with the victim. When launched, the signed binary utilizes DLL sideloading to silently load the malicious library into memory.

Stage 5: Payload Deployment and Process Branching

Once the initial execution is successful, the process tree reveals that the malware creates a child instance of itself. This behavior is indicative of the malware unpacking its core payload into the new process, effectively transitioning from the loader stage to the active stealer logic.

ANY.RUN’s Interactive Sandbox detects OnyxC2 fast ANY.RUN’s Interactive Sandbox detects OnyxC2 fast

Stage 6: Data Harvesting and Remote Access

With the payload fully deployed, OnyxC2 initiates its primary functions: harvesting credentials, session cookies, and financial data from over 200 targeted applications. If the "premium" build is utilized, the malware also activates advanced remote access features, such as HVNC over a web browser and LSASS memory dumping, granting the operator total control over the compromised workstation.

How Businesses Can Use ANY.RUN’s Threat Intelligence Against OnyxC2

Because OnyxC2 operates as a Malware-as-a-Service (MaaS) with infrastructure that rotates rapidly, traditional static blocklists are often insufficient for long-term protection. Security teams must shift from tracking temporary indicators to identifying the durable technical fingerprints and behavioral patterns of the operation. By leveraging ANY.RUN’s Threat Intelligence, organizations can stay ahead of these evolving campaigns.

Threat Intelligence Lookup allows analysts to pivot from a single suspicious artifact to an entire cluster of related malicious activity by searching for the "technical DNA" of the malware.

The following TI Lookup query reveals that the malware is linked to attacks on organizations in tech, government, and education from countries like Canada, Israel and the UK.

threatName:"onyxc2"

ANY.RUN’s TI Lookup reveals full threat landscape related to OnyxC2 ANY.RUN’s TI Lookup reveals full threat landscape related to OnyxC2

OnyxC2 consistently uses DLL sideloading, where a legitimate, signed binary (such as ABRSubProcess.exe by ACCA software S.p.A.) is used to load a malicious DLL (like borlndmm.dll). Security teams can use TI Lookup to search for these specific file name combinations or the Authenticode signatures of the legitimate hosts used in the attack chain. Even when domains change, the underlying assets of the phishing pages, such as the specific scripts used for Canvas fingerprinting to vet victims, remain stable. Analysts can search for these behavioral signatures to identify new phishing URLs before they are widely reported.

For organizations that require automated, high-speed protection, ANY.RUN’s Threat Intelligence Feeds provide a real-time stream of validated indicators. The feeds deliver a continuous flow of the latest C2 domains, IP addresses, and malicious URLs directly into SIEM, SOAR, and EDR platforms. The intel is extracted from the latest malware & phishing investigations of ANY.RUN’s global community of 15K organizations and 600K analysts.

By integrating these feeds, teams can automatically block emerging malicious infrastructure, such as the newly created phishing pages used to harvest credentials. Since OnyxC2 often deploys secondary tools like HVNC or reverse shells, the feeds provide critical network indicators for these remote management protocols, allowing teams to detect active breaches before data exfiltration occurs.

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

OnyxC2 represents the industrialization of modern cybercrime, providing low-skilled threat actors with a sophisticated platform for large-scale credential theft and account takeover. Its primary danger lies in its move beyond simple password harvesting; by targeting the session cookies and 2FA material that survive a password reset, it grants attackers "standing visibility" into a victim's entire digital working life.

To combat this threat, organizations must move beyond static blocklists and reactive defenses. Because OnyxC2 is sold as a Service (MaaS) with rapidly rotating infrastructure, successful mitigation depends on identifying the durable technical fingerprints. Implementing interactive sandboxing and proactive threat intelligence is essential to deobfuscate encrypted payloads and identify the modular remote access features, such as HVNC, that allow operators to inherit authenticated user sessions outright.

Frequently Asked Questions: OnyxC2

1. What is OnyxC2?

OnyxC2 is a sophisticated Malware-as-a-Service (MaaS) stealer and remote access toolkit that targets browsers, crypto wallets, and business-critical tools like FTP clients. It is sold on a subscription basis, allowing affiliates to deploy high-volume campaigns for a monthly fee.

2. How does OnyxC2 bypass traditional antivirus software?

The malware utilizes DLL sideloading, where a legitimate, signed executable is used to load a malicious DLL disguised as a system library. Because the primary executable carries a valid Authenticode signature, it often results in zero detections by automated security scanners.

3. Why is the "premium" version of OnyxC2 particularly dangerous for businesses?

The premium tier includes a modular remote access toolkit featuring HVNC (Hidden Virtual Network Computing) and LSASS memory dumping. These features allow an attacker to inherit a victim's authenticated browser session and perform actions in the background without the user's knowledge, bypassing MFA entirely.

4. How can organizations mitigate this threat?

Companies must integrate interactive sandboxing and proactive threat intelligence to expose the modular logic that evades traditional scanners. By using tools like TI Lookup and TI Feeds, security teams can identify stable build-chain fingerprints and block rotating infrastructure in real-time.

5. What types of applications does OnyxC2 target?

The stealer scrapes data from Chromium-based and Gecko-based browsers, as well as 2FA extensions and password managers. It specifically targets business systems like email and VPN clients to move beyond consumer theft and into corporate infrastructure.

HAVE A LOOK AT

StrelaStealer screenshot
StrelaStealer
strela
StrelaStealer is a malware that targets email clients to steal login credentials, sending them back to the attacker’s command-and-control server. Since its emergence in 2022, it has been involved in numerous large-scale email campaigns, primarily affecting organizations in the EU and U.S. The malware’s tactics continue to evolve, with attackers frequently changing attachment file formats and updating the DLL payload to evade detection.
Read More
Tykit screenshot
Tykit
tykit
Tykit is a sophisticated phishing-as-a-service (PhaaS) kit that emerged in May 2025, designed to steal Microsoft 365 corporate credentials through an innovative attack vector: malicious SVG files.
Read More
X-Files screenshot
X-Files
xfiles
X-FILES Stealer is a sophisticated malware designed to infiltrate systems and steal sensitive information, targeting login credentials for email, social media, and other personal accounts. It captures data and transmits it back to the attacker’s command-and-control server. X-FILES Stealer employs advanced evasion techniques to avoid detection, making it a persistent threat in the cyber landscape.
Read More
WhiteSnake screenshot
WhiteSnake
whitesnake
WhiteSnake is a stealer with advanced remote access capabilities. The attackers using this malicious software can control infected computers and carry out different malicious activities, including stealing sensitive files and data, recording audio, and logging keystrokes. WhiteSnake is sold on underground forums and often spreads through phishing emails.
Read More
BQTLock screenshot
BQTLock
bqtlock baqiyatlock
BQTLock is a ransomware-as-a-service (RaaS) malware family that emerged in 2025 and quickly gained attention due to its combination of file encryption, credential theft, and data exfiltration. BQTLock encrypts files using a hybrid AES-256 and RSA-4096 encryption scheme, demands payment in Monero cryptocurrency, and performs data theft and system reconnaissance.
Read More
Zloader screenshot
Zloader
zloader trojan loader
Zloader is a banking trojan that uses webinjects and VNC clients to still banking credentials. This Trojan is based on leaked code from 2011, but despite its age, Zloader’s popularity has been only increasing through early 2020, when it relied on COVID-19 themed attacks.
Read More