OnyxC2 Malware-as-a-Service: C++/Assembly Credential Stealer, HVNC RAT, and Reverse SOCKS5/Tor Toolkit Targeting 210+ Applications — Threadlinqs Intelligence
As of 2026-06-12, OnyxC2 Malware-as-a-Service: C++/Assembly Credential Stealer, HVNC RAT, and Reverse SOCKS5/Tor Toolkit Targeting 210+ Applications is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-0783 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
OnyxC2 is a commercially developed Malware-as-a-Service infostealer and remote-access toolkit sold from $250/month that harvests browser credentials, password-manager vaults, 2FA codes, and
OnyxC2 is an enterprise-grade Malware-as-a-Service (MaaS) infostealer and remote-access toolkit documented by BlackFog researchers in a report published June 11-12, 2026. It is marketed and sold like commercial software with tiered subscriptions: a 'Normal' tier at $250/month, a 'Premium' tier at $500/month that adds HVNC, and a 'Private' tier at roughly $6,000 that delivers source code plus installation support. The developer offers refunds if a build is detected, and advertises a '99% evasion rate' achieved by mutating every build prior to delivery to defeat antivirus signature matching.
The malware is written in C++ and uses assembly to issue direct syscalls and bypass user-mode security hooks. Two analyzed builds arrived clean on VirusTotal upload (0/71 engines on the signed host executable) as of May 30, 2026; at runtime only 2 of 18 antivirus engines flagged the payload. Each customer build supports EXE and DLL output formats and AES-256 encryption of payloads and build downloads.
Data-theft scope spans 210+ applications across nine categories: 37 Chromium-based browsers, 8 Gecko-based browsers, 95 Chromium and 14 Gecko browser extensions (including 6 dedicated 2FA tools), 5 password managers, 17 cryptocurrency wallets, 11 FTP clients, 5 email clients, and additional VPN, remote-access, messaging, note-taking, and gaming applications. A single infected host shown in the operator panel had already yielded 55 saved passwords, 4,717 cookies, 719 autofill entries, two payment cards, and a cryptocurrency wallet.
The remote-access toolkit lets operators run HVNC (hidden virtual network computing) to drive a concealed browser session, dump LSASS for credential access, execute payloads via RunPE both in-memory and on disk, open a reverse SOCKS5 proxy and a reverse shell over HTTP, capture screenshots, log keystrokes, manage files, and pivot through a built-in Tor tunnel for anonymized C2.
Delivery uses DLL sideloading: a legitimately signed Authenticode binary is paired with a malicious DLL that mimics a library name the signed program loads at startup. The malicious DLL is bloated past 120 MB by imitating an NVIDIA graphics library, and its payload is encrypted and only decrypted at runtime — a deliberate tactic to exceed antivirus file-scanning size/time limits. Observed lure binaries and archives impersonate legitimate utilities (Fling-Standalone, FinePrint), Windows components (SystemSettings.exe), and fake Windows-update ZIPs delivered as password-protected archives. Persistence is established via scheduled-task autorun and self-copying loader functionality. Command and control runs over Cloudflare-fronted HTTPS to the domain akmuniverstall[.]top using the default endpoint path /backend/api/app.php. No specific APT or named criminal group has been attributed; OnyxC2 is operated under a commercial MaaS model with an undetermined developer.
Weaknesses (CWE)
CWE-427, CWE-522, CWE-300
Target sectors: financial, technology, cryptocurrency, enterprise, individuals
Target regions: Global
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1588, T1583, T1587, T1204, T1106, T1053, T1053, T1574, T1574, T1055