news.mlab.sh
Back to the feed
malware

OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month

High
Summary

The OnyxC2 stealer, offered as a "Malware-as-a-Service" (MaaS) product for $250-$500 per month, is a sophisticated tool designed for enterprise-level credential theft. Developed by BlackFog, it boasts a wide range of targets including browsers, password managers, cryptocurrency wallets, and VPNs, and utilizes advanced techniques like persistence and stealth. The emergence of OnyxC2 highlights the increasing sophistication and commercialization of infostealer threats.

OnyxC2 is a commercially available stealer that has gained attention due to its extensive feature set and relatively affordable pricing. Offered through a MaaS model, it provides access to a vast array of targets, including 37 Chromium-based browsers, 8 Gecko-based browsers, and numerous extensions, password managers, and cryptocurrency wallets. Researchers at BlackFog analyzed two samples, noting the stealer’s commercial-like development and support, which allows less technically skilled users to deploy it effectively. The package includes pre-made lures like FinePrint and fake Windows update packages, further enhancing its effectiveness.

The stealer’s capabilities extend beyond simple credential theft, targeting FTP clients, email clients, and even gaming applications. It employs techniques such as LSASS dumping, RunPE in memory, and a reverse SOCKS5 proxy to maximize data collection. The build incorporates AES-256 encryption and a legitimate application with a valid Authenticate signature to evade detection, and utilizes a disguised NVIDIA graphics library payload. BlackFog confirmed the stealer’s stealth through VirusTotal, with both delivery archives returning clean and the malicious component remaining unflagged as of May 30, 2026.

This level of sophistication and commercialization underscores the growing threat of infostealers. The availability of tools like OnyxC2 empowers cybercriminals to conduct targeted attacks against businesses and individuals, highlighting the need for robust security measures and proactive threat intelligence. The continuous development and refinement of such tools suggests a persistent and evolving threat landscape.

Read the full article at SecurityWeek