Inside OnyxC2: The New Stealer Targeting 210 Apps
June 15, 2026, 5:15 p.m.
Description
OnyxC2 emerged in early 2026 as a malware-as-a-service stealer sold on cybercrime networks for $250 monthly. The platform includes a web panel, payload builder, and tiered pricing structure with refund guarantees. Written in C++ with assembly for direct syscalls, it targets approximately 210 applications across nine categories: 45 browsers, 109 extensions including 2FA tools, 5 password managers, 17 cryptocurrency wallets, 11 FTP clients, 5 email clients, and VPN/messaging applications. The stealer achieves 99% detection evasion through mutated builds and delivers via DLL sideloading using signed binaries. Higher tiers unlock remote access capabilities including HVNC, LSASS dumping, reverse SOCKS5 proxy, keylogging, and reverse shell. Distribution occurs through fake installers delivered as password-protected archives, with C2 communication over Cloudflare-fronted HTTPS to akmuniverstall.top.
Tags
Date
- Created: June 15, 2026, 2:58 p.m.
- Published: June 15, 2026, 2:58 p.m.
- Modified: June 15, 2026, 5:15 p.m.
Indicators
- 78945c844fc23dd3446cf17987edeeb6cc21986820c92df82a126af24a5a38d1
- 41999a3d0da035ff8068905c90235ea50121329cb0661e38d745974ebf5e3ae2
- d89bb4b23a67814ef511e4e9dda7ad36fa519a322fa7c25ea451c7dd7ef61e54
- f6e4b09ef788adef3f65fd2b99da8f5be5391be29471676dc07040a56c8fdfab
Additional Informations
- akmuniverstall.top