Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Government Directive Blocks Anthropic Fable 5 & Mythos Access
June 13, 2026
Fancy Bear Abuses EdgeRouters & Cloud for Stealthy
June 12, 2026
Hackers Abuse NinjaOne RMM to Bypass Malware Legitimate Software
June 12, 2026
Home/Threats/OnyxC2 MaaS Hackers Steal Credentials Malware-as-a-Service From
Threats

OnyxC2 MaaS Hackers Steal Credentials Malware-as-a-Service From

A potent new credential-stealing tool, OnyxC2, has surfaced within the cybercrime underground. Operating as a malware-as-a-service (MaaS), it dramatically lowers the bar for entry, allowing even...

Jennifer sherman
Jennifer sherman
June 12, 2026 4 Min Read
6 0

A potent new credential-stealing tool, OnyxC2, has surfaced within the cybercrime underground. Operating as a malware-as-a-service (MaaS), it dramatically lowers the bar for entry, allowing even low-skilled threat actors to conduct sophisticated operations. This capability enables them to steal credentials from over Sold as a complete package for $250 a month, the malware gives buyers everything they need to quietly drain login data from victims worldwide. What makes it stand out is the scale of what it targets: over 210 applications and browser extensions in one sweep.

OnyxC2 is marketed like legitimate commercial software, complete with a web panel, a payload builder, tiered pricing, and refunds if a build gets flagged.

For a monthly fee, buyers get a kit that steals browser credentials, password manager data, two-factor authentication codes, and crypto wallet information. The stolen data is shipped back through an encrypted channel, making it harder for security tools to catch in transit.

Analysts at Blackfog identified the malware and published their findings in a report shared with Cyber Security News (CSN), revealing the full scope of what OnyxC2 can do and how it evades detection.

The research team obtained live builds, ran them in sandbox environments, and confirmed that the tool is actively reaching live command-and-control infrastructure.

The malware is written in C++, using assembly code to bypass security rules at the system level. Each build is mutated before delivery to break antivirus signature detection, and the developer claims a 99% evasion rate.

OnyxC2 dashboard harvest totals (Source - Blackfog)
OnyxC2 dashboard harvest totals (Source – Blackfog)

Blackfog’s tests confirmed this: both sample builds submitted to VirusTotal came back clean on first upload, with the malicious component still undetected as of May 30, 2026.

The damage potential is very real. One infected machine shown in the panel had already surrendered 55 saved passwords, 4,717 cookies, 719 autofill entries, credit card data, and a crypto wallet, all from a single host.

That kind of haul can unlock banking systems, business accounts, and cloud services in one shot.

Hackers Use OnyxC2 Malware-as-a-Service

The breadth of OnyxC2’s target list sets it apart from simpler stealers. It reaches 37 Chromium-based browsers and 8 Gecko-based browsers, plus 95 Chromium and 14 Gecko extensions, including 6 dedicated two-factor authentication tools. Even accounts protected by 2FA are not safe from this threat.

OnyxC2 license tiers and pricing (Source - Blackfog)
OnyxC2 license tiers and pricing (Source – Blackfog)

The stealer also covers 5 password managers, 17 cryptocurrency wallets, 11 FTP clients, and 5 email clients. A stealer that grabs password manager data alongside active session cookies can access accounts even after a victim changes their password.

The FTP and email targets push its reach beyond personal accounts and into business systems that finance and operations teams use every day.

Beyond credential theft, OnyxC2 bundles a full remote-access toolkit. Operators can use HVNC to control a hidden browser session, run a keylogger, take screenshots, and manage files remotely.

OnyxC2 builder with backend path (Source - Blackfog)
OnyxC2 builder with backend path (Source – Blackfog)

A reverse SOCKS5 proxy and a built-in Tor tunnel round out the toolkit, letting attackers route traffic anonymously.

Fake Installer Delivery and Evasion

OnyxC2 reaches victims through fake installer packages disguised as legitimate software downloads. The lures found by researchers included packages mimicking Fling-Standalone, FinePrint, SystemSettings, and fake Windows update files.

Each malicious archive is password-protected, helping it slip past automated scanning tools that must open files to inspect them.

Inside each fake archive is a two-file package built for DLL sideloading. The first file is a legitimately signed application that Windows trusts without question, and the second is a malicious DLL named to match a library the signed program loads at startup.

When the victim runs what looks like an installer, the trusted program unknowingly loads the attacker’s code from the same folder.

The malicious DLL is bloated past 120 MB by mimicking a real NVIDIA graphics library, with genuine-looking exported function names embedded inside.

Many antivirus scanners skip large files to save time, and the actual payload sits encrypted inside, only decrypting at runtime.

Blackfog recommends enforcing anti-data-exfiltration controls at the endpoint, blocking outbound data transfers at the point of theft rather than relying solely on file scanning.

Indicators of Compromise:-

Type Indicator Description
Domain akmuniverstall.top C2 and distribution domain (13/94 detections on VirusTotal) 
URL Path /backend/api/app.php C2 endpoint path written by the builder by default 
IP Address 104.18.20.213 Cloudflare fronting IP associated with C2 infrastructure 
IP Address 104.21.46.39 Cloudflare fronting IP associated with C2 infrastructure 
IP Address 172.67.223.39 Cloudflare fronting IP associated with C2 infrastructure 
SHA-256 41999a3d0da035ff8068905c90235ea50121329cb0661e38d745974ebf5e3ae2 Signed sideload host executable (Setup_File_75.593.2113.exe / Setup_File_27.430.4673.exe); 0/71 detections 
SHA-256 78945c844fc23dd3446cf17987edeeb6cc21986820c92df82a126af24a5a38d1 Malicious DLL (borlndmm.dll) — Build 1 
SHA-256 d89bb4b23a67814ef511e4e9dda7ad36fa519a322fa7c25ea451c7dd7ef61e54 Malicious DLL (borlndmm.dll) — Build 2 
SHA-256 f6e4b09ef788adef3f65fd2b99da8f5be5391be29471676dc07040a56c8fdfab Delivery archive (password-protected ZIP) 
Filename Fling-Standalone*, FinePrint*, SystemSettings.exe Lure filenames used in fake installer packages 
Filename Fake Windows update ZIPs Additional lure packages used in distribution campaign 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Google Sues Chinese Cybercrime for Gemini AI Cyberattacks

Next Post

Malicious npm Campaign Steals SSH Keys & Cloud Credentials

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Google Sues Chinese Cybercrime for Gemini AI Cyberattacks
June 12, 2026
Arch Linux AUR Supply Chain Attack Deploys Infostealers
June 12, 2026
Critical LangGraph Vulnerability Gives Attackers Full Server Control
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us