Onyx is a ransomware operation first observed in 2022 that conducts double-extortion attacks, stealing victim data and then encrypting systems while threatening public disclosure on a leak site if payment is not made. The group has also been associated with a leak site later renamed VSOP NEWS. Technical analysis has linked Onyx ransomware to the Chaos ransomware codebase. The malware is implemented in .NET, uses AES and RSA for encryption, targets common user data and a broad range of file types, deletes shadow copies and backup catalogs to impede recovery, establishes persistence, and attempts to spread via mounted drives. A notable operational characteristic is that files larger than roughly 2 MB may be overwritten with random data rather than recoverably encrypted, causing irreversible destruction and potentially undermining decryption-based recovery. Victim reporting indicates activity across multiple countries, with the United States accounting for the majority of publicly listed victims in early observed campaigns. Reporting has also noted overlap between at least one victim listed by Onyx and one listed by Conti, suggesting possible affiliate overlap or operator migration during the period when Conti was fragmenting, although any deeper organizational relationship remains unconfirmed. Separately, the name Onyx Sleet is used by Microsoft for a North Korean state-linked threat actor distinct from the Onyx ransomware group. That actor has been reported exploiting CVE-2023-42793 in JetBrains TeamCity for remote code execution against targets in Europe. Because these are separate clusters that share the word "Onyx," they should not be conflated.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North Korea-linked activity leveraging TeamCity RCE (CVE-2023-42793) consistent with software/supply-chain targeting.
Ransomware operations using double extortion, including data exfiltration, file encryption, leak-site operations, and later rebranding its leak site from 'ONYX NEWS' to 'VSOP NEWS'. The content also notes Onyx is based on Chaos ransomware and that it may have resumed activity after a period of inactivity.
Named ransomware operation noted for overwriting large files, preventing recovery even if a decryptor were obtained.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.