惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
有赞技术团队
有赞技术团队
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
U
Unit 42
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Recent Announcements
Recent Announcements
Y
Y Combinator Blog
Vercel News
Vercel News
Martin Fowler
Martin Fowler
V
V2EX
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
L
LangChain Blog
云风的 BLOG
云风的 BLOG
H
Hackread – Cybersecurity News, Data Breaches, AI and More
aimingoo的专栏
aimingoo的专栏
G
Google Developers Blog
The GitHub Blog
The GitHub Blog
N
Netflix TechBlog - Medium
Google DeepMind News
Google DeepMind News
雷峰网
雷峰网
阮一峰的网络日志
阮一峰的网络日志
F
Fortinet All Blogs

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data
Hackers Use OnyxC2 Malware-as-a-Service to Steal Credenti...
Tushar Subhra Dutta · 2026-06-12 · via Cyber Security News

A new and dangerous credential-stealing tool called OnyxC2 has emerged in the cybercrime underground, showing just how easy it has become for even low-skilled attackers to run a professional hacking operation.

Sold as a complete package for $250 a month, the malware gives buyers everything they need to quietly drain login data from victims worldwide. What makes it stand out is the scale of what it targets: over 210 applications and browser extensions in one sweep.

OnyxC2 is marketed like legitimate commercial software, complete with a web panel, a payload builder, tiered pricing, and refunds if a build gets flagged.

For a monthly fee, buyers get a kit that steals browser credentials, password manager data, two-factor authentication codes, and crypto wallet information. The stolen data is shipped back through an encrypted channel, making it harder for security tools to catch in transit.

Analysts at Blackfog identified the malware and published their findings in a report shared with Cyber Security News (CSN), revealing the full scope of what OnyxC2 can do and how it evades detection.

The research team obtained live builds, ran them in sandbox environments, and confirmed that the tool is actively reaching live command-and-control infrastructure.

The malware is written in C++, using assembly code to bypass security rules at the system level. Each build is mutated before delivery to break antivirus signature detection, and the developer claims a 99% evasion rate.

OnyxC2 dashboard harvest totals (Source - Blackfog)
OnyxC2 dashboard harvest totals (Source – Blackfog)

Blackfog’s tests confirmed this: both sample builds submitted to VirusTotal came back clean on first upload, with the malicious component still undetected as of May 30, 2026.

The damage potential is very real. One infected machine shown in the panel had already surrendered 55 saved passwords, 4,717 cookies, 719 autofill entries, credit card data, and a crypto wallet, all from a single host.

That kind of haul can unlock banking systems, business accounts, and cloud services in one shot.

Hackers Use OnyxC2 Malware-as-a-Service

The breadth of OnyxC2’s target list sets it apart from simpler stealers. It reaches 37 Chromium-based browsers and 8 Gecko-based browsers, plus 95 Chromium and 14 Gecko extensions, including 6 dedicated two-factor authentication tools. Even accounts protected by 2FA are not safe from this threat.

OnyxC2 license tiers and pricing (Source - Blackfog)
OnyxC2 license tiers and pricing (Source – Blackfog)

The stealer also covers 5 password managers, 17 cryptocurrency wallets, 11 FTP clients, and 5 email clients. A stealer that grabs password manager data alongside active session cookies can access accounts even after a victim changes their password.

The FTP and email targets push its reach beyond personal accounts and into business systems that finance and operations teams use every day.

Beyond credential theft, OnyxC2 bundles a full remote-access toolkit. Operators can use HVNC to control a hidden browser session, run a keylogger, take screenshots, and manage files remotely.

OnyxC2 builder with backend path (Source - Blackfog)
OnyxC2 builder with backend path (Source – Blackfog)

A reverse SOCKS5 proxy and a built-in Tor tunnel round out the toolkit, letting attackers route traffic anonymously.

Fake Installer Delivery and Evasion

OnyxC2 reaches victims through fake installer packages disguised as legitimate software downloads. The lures found by researchers included packages mimicking Fling-Standalone, FinePrint, SystemSettings, and fake Windows update files.

Each malicious archive is password-protected, helping it slip past automated scanning tools that must open files to inspect them.

Inside each fake archive is a two-file package built for DLL sideloading. The first file is a legitimately signed application that Windows trusts without question, and the second is a malicious DLL named to match a library the signed program loads at startup.

When the victim runs what looks like an installer, the trusted program unknowingly loads the attacker’s code from the same folder.

The malicious DLL is bloated past 120 MB by mimicking a real NVIDIA graphics library, with genuine-looking exported function names embedded inside.

Many antivirus scanners skip large files to save time, and the actual payload sits encrypted inside, only decrypting at runtime.

Blackfog recommends enforcing anti-data-exfiltration controls at the endpoint, blocking outbound data transfers at the point of theft rather than relying solely on file scanning.

Indicators of Compromise:-

TypeIndicatorDescription
Domainakmuniverstall.topC2 and distribution domain (13/94 detections on VirusTotal) 
URL Path/backend/api/app.phpC2 endpoint path written by the builder by default 
IP Address104.18.20.213Cloudflare fronting IP associated with C2 infrastructure 
IP Address104.21.46.39Cloudflare fronting IP associated with C2 infrastructure 
IP Address172.67.223.39Cloudflare fronting IP associated with C2 infrastructure 
SHA-25641999a3d0da035ff8068905c90235ea50121329cb0661e38d745974ebf5e3ae2Signed sideload host executable (Setup_File_75.593.2113.exe / Setup_File_27.430.4673.exe); 0/71 detections 
SHA-25678945c844fc23dd3446cf17987edeeb6cc21986820c92df82a126af24a5a38d1Malicious DLL (borlndmm.dll) — Build 1 
SHA-256d89bb4b23a67814ef511e4e9dda7ad36fa519a322fa7c25ea451c7dd7ef61e54Malicious DLL (borlndmm.dll) — Build 2 
SHA-256f6e4b09ef788adef3f65fd2b99da8f5be5391be29471676dc07040a56c8fdfabDelivery archive (password-protected ZIP) 
FilenameFling-Standalone*, FinePrint*, SystemSettings.exeLure filenames used in fake installer packages 
FilenameFake Windows update ZIPsAdditional lure packages used in distribution campaign 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.