OnyxC2 Malware-as-a-Service Targeting 200+ Applications
Score: 8/10

OnyxC2 Malware-as-a-Service Targeting 200+ Applications

OnyxC2 is a sophisticated Malware-as-a-Service info-stealer and remote access toolkit targeting over 200 applications including crypto wallets, browsers, and 2FA extensions.

Executive Summary

OnyxC2 is a sophisticated Malware-as-a-Service (MaaS) platform first identified in early 2026, marketed for high-volume credential theft and persistent account takeover. It represents an industrialized shift in cybercrime, providing low-skilled affiliates with modular tools to harvest session cookies and 2FA backup data, effectively bypassing modern multi-factor authentication.

The malware's technical chain is notable for its use of DLL sideloading via legitimate signed binaries (such as those from ACCA software S.p.A.) and canvas fingerprinting to vet potential victims. Beyond standard data harvesting, its 'premium' tier offers advanced capabilities including Hidden Virtual Network Computing (HVNC) and LSASS memory dumping, granting attackers complete remote control over compromised infrastructure. Its broad targeting of over 200 applications—ranging from financial tools to business-critical systems—poses a significant risk to the cryptocurrency, government, and technology sectors.

Key Details

Threat Name

OnyxC2

Affects

—

Adversary

Lazarus Group

Malware/Tools

OnyxC2, ValleyRAT, XRed, Agent Tesla, zgRAT, Phorpiex, DarkVision, Meduza Stealer, Venom Stealer, Infiniti Stealer, BoryptGrab Stealer, AmnesiaStealer

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance6
Enterprise Relevance9
Clarity & Structure9
Technical Depth8

Sources