Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month

0
Medium
Malware
Published: Thu Jun 11 2026 (06/11/2026, 13:00:00 UTC)
Source: SecurityWeek

Description

Researchers say the OnyxC2 malware targets more than 200 applications and extensions while evading detection through encrypted payloads, DLL sideloading, and in-memory execution techniques. The post OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month appeared first on SecurityWeek .

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/11/2026, 13:08:14 UTC

Technical Analysis

OnyxC2 is a commercial-grade stealer malware available via Malware-as-a-Service starting at $250 monthly. It targets approximately 210 applications and extensions across nine categories, including browsers (Chromium and Gecko-based), password managers, cryptocurrency wallets, FTP clients, and email clients. The malware employs encrypted payloads, DLL sideloading (disguised as legitimate NVIDIA DLLs), and in-memory execution to evade detection. It includes a remote-access toolkit with features such as hidden VNC over a browser, LSASS dumping, RunPE, reverse SOCKS5 proxy, keylogger, file manager, reverse shell over HTTP, TOR tunneling, and AES-256 encrypted build downloads. The malware's stealth is confirmed by clean VirusTotal scans upon initial detection. The developers offer multiple purchase options, including a private source code sale. The malware's capabilities enable extensive credential and session data theft, persistence, and standing access to victim systems.

Potential Impact

OnyxC2 enables attackers to steal credentials, cookies, autofill data, payment cards, and cryptocurrency wallets from infected hosts, compromising both consumer and business systems. Its ability to harvest data from password managers and two-factor authentication extensions increases the risk of account takeover even after password resets. The malware's persistence and stealth techniques allow prolonged unauthorized access. The inclusion of remote-access tools facilitates further system control and data exfiltration. The malware's initial samples were undetected by antivirus engines, increasing the likelihood of successful infections.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Given the malware's stealth and evasion techniques, organizations should rely on updated endpoint detection and response solutions capable of detecting DLL sideloading and in-memory execution. Network monitoring for unusual outbound connections, especially TOR traffic and reverse proxies, may help identify infections. User education to avoid executing suspicious installers and lures is recommended. Since this is a malware-as-a-service offering, blocking known command and control infrastructure and threat intelligence sharing are important. No official fix or patch is available as this is malware rather than a software vulnerability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.securityweek.com/onyxc2-stealer-offers-cybercriminals-enterprise-grade-theft-for-250-a-month/","fetched":true,"fetchedAt":"2026-06-11T13:07:53.046Z","wordCount":1370}

Threat ID: 6a2ab32957b0f63cf3ab3b48

Added to database: 6/11/2026, 1:07:53 PM

Last enriched: 6/11/2026, 1:08:14 PM

Last updated: 6/11/2026, 4:28:53 PM

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses