Last seven days
- First activity
- Jul 25, 2026
- Last activity
- Jul 25, 2026
- Feed role
- C2 / Distribution
- Host form
- 0 IP / 1 hostnames
OnyxC2 is a malware-as-a-service (MaaS) infostealer that emerged on cybercrime forums in early 2026 and is marketed as a low-cost, enterprise-grade credential theft and remote access platform.
Profile source: Mallory opens in a new tabOnyxC2
OnyxC2 is a malware-as-a-service (MaaS) infostealer that emerged on cybercrime forums in early 2026 and is marketed as a low-cost, enterprise-grade credential theft and remote access platform. It is sold in subscription tiers, including a standard build for $250 per month, a premium build for $500 per month that includes HVNC, and source code offered for $6,000. The service includes a web-based control panel and builder, with panel sections such as bots, logs, builder, users, and settings, as well as support, cloud storage, AES-256-encrypted build downloads, and refund promises if a build is detected.
Based on the provided reporting, OnyxC2 targets more than 210 applications across multiple categories, including 37 Chromium-based browsers, 8 Gecko-based browsers, 95 Chromium browser extensions, 14 Gecko browser extensions including 6 dedicated two-factor authentication extensions, 5 password managers, 17 cryptocurrency wallets, 11 FTP clients, and 5 email clients. Additional reporting states it also targets VPN, remote access, messaging, note-taking, and gaming applications. It is designed to steal saved passwords, cookies, autofill data, payment card data, cryptocurrency wallet information, and active session cookies, enabling session hijacking even after password changes.
OnyxC2 also includes broader post-compromise and remote access functionality. Reported capabilities include HVNC, keylogging, screenshot capture, file management, reverse SOCKS5 proxying, Tor tunneling, reverse shell over HTTP, LSASS memory dumping, and RunPE execution in memory and on disk.
The malware uses multiple evasion and delivery techniques. Researchers reported DLL sideloading using legitimate signed applications bundled with malicious DLLs inside fake installer packages and password-protected archives. Observed lure installers impersonated FinePrint, SystemSettings, fake Windows update packages, and Fling-Standalone. The malicious DLL was described as padded beyond 120-130 MB, disguised as an NVIDIA graphics library with realistic export names, and containing an encrypted payload that decrypts only at runtime. Reporting also states that parts of execution occur in memory, builds are mutated before delivery, and one signed host executable scored 0/71 detections on VirusTotal. BlackFog reported both analyzed delivery archives were initially clean on VirusTotal, and the malicious component remained unflagged as of May 30, 2026.
BlackFog researchers obtained and analyzed two samples, executed live builds in sandbox environments, and confirmed communication with live command-and-control infrastructure. In one observed infection shown in the operator panel, a single compromised host yielded 55 saved passwords, 4,717 cookies, 719 autofill entries, 2 payment cards, and 1 cryptocurrency wallet.
High-confidence indicators mentioned in the content include the domain akmuniverstall.top, the default C2 endpoint path /backend/api/app.php, and Cloudflare-fronted IP addresses 104.18.20.213, 104.21.46.39, and 172.67.223.39.
C2 tracking
Derp observations, rolling seven-day window
Samples
20071046c38bd051d505fc3cc520faf362be5ae54708bd8601f2b9a17e56a803 22cdabe7a3d51b6127d31241ef4252b327f1341d75723c9e173d8eaecc0e05eb 30f9795402b7259e9bd867fc45a8c3a1996085292c300f782af53980b8567649 cab25f1867d76e6fa0a4220867136498ecfed04c6dd8d4f15f6758ba4ad0f02b eb50427b69f78bc6aee4ad861138acbbff7f7982344ee976ad32e3cf25d00014 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.