OnyxC2 is a malware-as-a-service (MaaS) infostealer that emerged on cybercrime forums in early 2026 and is marketed as a low-cost, enterprise-grade credential theft and remote access platform. It is sold in subscription tiers, including a standard build for $250 per month, a premium build for $500 per month that includes HVNC, and source code offered for $6,000. The service includes a web-based control panel and builder, with panel sections such as bots, logs, builder, users, and settings, as well as support, cloud storage, AES-256-encrypted build downloads, and refund promises if a build is detected.
Based on the provided reporting, OnyxC2 targets more than 210 applications across multiple categories, including 37 Chromium-based browsers, 8 Gecko-based browsers, 95 Chromium browser extensions, 14 Gecko browser extensions including 6 dedicated two-factor authentication extensions, 5 password managers, 17 cryptocurrency wallets, 11 FTP clients, and 5 email clients. Additional reporting states it also targets VPN, remote access, messaging, note-taking, and gaming applications. It is designed to steal saved passwords, cookies, autofill data, payment card data, cryptocurrency wallet information, and active session cookies, enabling session hijacking even after password changes.
OnyxC2 also includes broader post-compromise and remote access functionality. Reported capabilities include HVNC, keylogging, screenshot capture, file management, reverse SOCKS5 proxying, Tor tunneling, reverse shell over HTTP, LSASS memory dumping, and RunPE execution in memory and on disk.
The malware uses multiple evasion and delivery techniques. Researchers reported DLL sideloading using legitimate signed applications bundled with malicious DLLs inside fake installer packages and password-protected archives. Observed lure installers impersonated FinePrint, SystemSettings, fake Windows update packages, and Fling-Standalone. The malicious DLL was described as padded beyond 120-130 MB, disguised as an NVIDIA graphics library with realistic export names, and containing an encrypted payload that decrypts only at runtime. Reporting also states that parts of execution occur in memory, builds are mutated before delivery, and one signed host executable scored 0/71 detections on VirusTotal. BlackFog reported both analyzed delivery archives were initially clean on VirusTotal, and the malicious component remained unflagged as of May 30, 2026.
BlackFog researchers obtained and analyzed two samples, executed live builds in sandbox environments, and confirmed communication with live command-and-control infrastructure. In one observed infection shown in the operator panel, a single compromised host yielded 55 saved passwords, 4,717 cookies, 719 autofill entries, 2 payment cards, and 1 cryptocurrency wallet.
High-confidence indicators mentioned in the content include the domain akmuniverstall.top, the default C2 endpoint path /backend/api/app.php, and Cloudflare-fronted IP addresses 104.18.20.213, 104.21.46.39, and 172.67.223.39.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The payload stays encrypted until runtime... The build downloads themselves are encrypted with AES-256.
the developer pads the malicious DLL to over 130 MB and disguises it as an NVIDIA graphics library — many antivirus engines skip large files entirely
The lures found by researchers included packages mimicking Fling-Standalone, FinePrint, SystemSettings, and fake Windows update files.
It includes HVNC over a web browser, LSASS memory dumping, RunPE execution both in memory and on disk...
The payload stays encrypted until runtime, so there’s nothing to detect on disk before execution begins.
For a monthly fee, buyers get a kit that steals browser credentials, password manager data, two-factor authentication codes, and crypto wallet information.
Credential Access T1003.001 LSASS Memory Dumping Premium tier includes LSASS dumping
Credential Access T1539 Steal Web Session Cookie Cookie theft across targeted browsers
The target list covers... 5 password managers... 'A stealer that scrapes password managers and 2FA extensions alongside saved logins...'
Credential Access T1555.003 Credentials from Web Browsers Targets 45 browsers total
The stolen data is shipped back through an encrypted channel, making it harder for security tools to catch in transit.
Stolen data is sent to the operator's panel via HTTPS... Command & Control T1071.001 Web Protocols HTTPS C2, Cloudflare-fronted
The stealer's capabilities extend beyond credential harvesting, incorporating features like High-Volume Network Interface (HVNC), LSASS memory dumping, and a reverse SOCKS5 proxy.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as a named stealer in a headline; no further behavioral details are provided in the content.
A Malware-as-a-Service infostealer that steals credentials, cookies, autofill data, payment cards, cryptocurrency wallets, and other sensitive data from over 210 applications. It uses DLL sideloading, encrypted payloads, in-memory execution, persistence mechanisms, and in premium tiers includes HVNC remote desktop control.
OnyxC2 is a credential-stealing malware sold as a malware-as-a-service offering. It steals browser credentials, password manager data, 2FA codes, crypto wallet information, cookies, autofill data, credit card data, and also includes remote-access capabilities such as HVNC, keylogging, screenshots, file management, reverse SOCKS5 proxying, and Tor tunneling. It is delivered via fake installer packages using DLL sideloading and employs mutation, encryption, and oversized DLL padding to evade detection.
A malware-as-a-service stealer sold on cybercrime forums that targets more than 210 applications, including browsers, extensions, password managers, cryptocurrency wallets, FTP clients, and email clients. It also includes HVNC, LSASS memory dumping, a reverse SOCKS5 proxy, DLL sideloading-based delivery, encrypted payloads at rest, and pre-made lure installers for distribution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.