216.73.216.6

Inside OnyxC2: The New Stealer Targeting 210 Apps

· Published 15/06/2026 14:58 · Modified 15/06/2026 17:15

Export JSON

Essential information

Published
15/06/2026 14:58
Modified
15/06/2026 17:15
Tags
2026-06-15 2fa theft credential-stealer cryptocurrency wallet dll sideloading malware-as-a-service onyxc2 password manager harvesting remote access
Related entities
4 observables, 15 techniques (mitre), 1 malware, 1 others

Description

emerged in early 2026 as a stealer sold on cybercrime networks for $250 monthly. The platform includes a web panel, payload builder, and tiered pricing structure with refund guarantees. Written in C++ with assembly for direct syscalls, it targets approximately 210 applications across nine categories: 45 browsers, 109 extensions including 2FA tools, 5 password managers, 17 cryptocurrency wallets, 11 FTP clients, 5 email clients, and VPN/messaging applications. The stealer achieves 99% detection evasion through mutated builds and delivers via using signed binaries. Higher tiers unlock capabilities including HVNC, LSASS dumping, reverse SOCKS5 proxy, keylogging, and reverse shell. Distribution occurs through fake installers delivered as password-protected archives, with C2 communication over Cloudflare-fronted HTTPS to akmuniverstall.top.

External references