Executive Summary
OnyxC2 is a sophisticated Malware-as-a-Service (MaaS) platform first identified in early 2026, marketed for high-volume credential theft and persistent account takeover. It represents an industrialized shift in cybercrime, providing low-skilled affiliates with modular tools to harvest session cookies and 2FA backup data, effectively bypassing modern multi-factor authentication.
The malware's technical chain is notable for its use of DLL sideloading via legitimate signed binaries (such as those from ACCA software S.p.A.) and canvas fingerprinting to vet potential victims. Beyond standard data harvesting, its 'premium' tier offers advanced capabilities including Hidden Virtual Network Computing (HVNC) and LSASS memory dumping, granting attackers complete remote control over compromised infrastructure. Its broad targeting of over 200 applications—ranging from financial tools to business-critical systems—poses a significant risk to the cryptocurrency, government, and technology sectors.
Key Details
Threat Name
OnyxC2
Affects
—
Adversary
Lazarus Group
MITRE Techniques
Malware/Tools
OnyxC2, ValleyRAT, XRed, Agent Tesla, zgRAT, Phorpiex, DarkVision, Meduza Stealer, Venom Stealer, Infiniti Stealer, BoryptGrab Stealer, AmnesiaStealer
