# OnyxC2 Stealer Brings Enterprise-Grade Credential Theft to $250-Per-Month Cybercriminals


Researchers uncover a sophisticated malware-as-a-service platform that targets 210+ applications, evades detection flawlessly, and democratizes credential harvesting for criminal operators without technical skill.


A newly discovered malware stealer called OnyxC2 is reshaping the economics of credential theft by packaging sophisticated, enterprise-grade theft capabilities into a subscription-based service starting at just $250 per month. Analysis by BlackFog researchers reveals a weapon designed to extract passwords, authentication tokens, cryptocurrency wallets, and session cookies from infected workstations with remarkable stealth—and it's already being actively marketed and deployed by cybercriminals.


The threat isn't novel in concept, but its execution and accessibility represent a troubling escalation. OnyxC2 combines industrial-strength evasion techniques, persistent access capabilities, and sweeping target coverage into a polished, well-supported product sold like legitimate enterprise software. This is malware designed not for sophisticated threat actors but for ordinary criminals who lack the technical expertise to build their own tools.


## The Threat: What OnyxC2 Does


OnyxC2 is a credential stealer sold as Malware-as-a-Service (MaaS). Once deployed on a target workstation, it systematically exfiltrates sensitive data from the victim's saved credentials, browser sessions, and installed applications. Its reach is staggering:


| Category | Targets |

|----------|---------|

| Chromium-based browsers | 37 |

| Gecko-based browsers | 8 |

| Chromium extensions | 95 |

| Gecko extensions | 14 |

| Password managers | 5 |

| Cryptocurrency wallets | 17 |

| FTP clients | 11 |

| Email clients | 5 |

| VPN/remote access/messaging tools | Multiple |


Total footprint: Approximately 210 applications and extensions across nine categories.


The payload is deliberately constructed to catch both personal and business credentials in a single sweep. One infected host analyzed by researchers had already surrendered:


  • 55 saved passwords
  • 4,717 cookies (session tokens for authenticated web access)
  • 719 autofill entries (saved usernames, addresses, payment details)
  • 2 stored payment cards
  • 1 cryptocurrency wallet

  • This combination matters enormously. Researchers note that OnyxC2 is explicitly built to harvest credentials and session material that survive password resets—a critical capability that transforms a single compromised workstation into persistent access across months or years of a victim's digital life.


    ## Pricing and Packaging: Malware as a Product


    OnyxC2's developers have adopted a commercial software model complete with tiered pricing, ready-made attack payloads, and refund guarantees—a striking indicator of how mature and confident this operation has become.


    Pricing tiers include:


  • Normal: $250 per month
  • Premium (with HVNC—Hidden VNC, a remote browser display tool): $500 per month
  • Private (complete source code + installation service): $6,000 (one-time)

  • The developers even offer refunds if their build is detected by antivirus software—a guarantee that signals both their technical confidence and their understanding of their customer base. Many operators can't afford to lose $250 on a failed infection, so guarantees reduce buyer hesitation.


    To further lower barriers to entry, the package includes ready-made social engineering lures disguised as:


  • FinePrint printer software
  • Windows system settings
  • Fake Windows Update packages
  • Standalone game launchers

  • These pre-built decoys mean operators don't need to craft their own convincing delivery mechanisms. They can simply rent OnyxC2, download a lure, and begin campaigns immediately.


    ## Technical Details: Stealth Through Sophistication


    OnyxC2's stealth capabilities explain its premium positioning within the stealer market. The malware employs multiple evasion techniques working in concert:


    ### Encrypted Delivery and Valid Code Signing


    The malware's build downloads are encrypted with AES-256. Once on the victim's machine, the stealer is delivered inside a legitimate application with a valid Microsoft Authenticode signature. In BlackFog's analysis, this legitimate component showed zero detections across 71 antivirus engines on VirusTotal. This level of evasion is the result of careful reverse-engineering: the researchers found that the developers obtained a legitimate application, appended the malicious DLL payload to the end of the file, and configured the installation process to load both simultaneously.


    ### DLL Sideloading


    The malicious component is disguised as an NVIDIA graphics library—a common Windows system component that antivirus tools are unlikely to flag. When the victim installs the "legitimate" application, the fake NVIDIA DLL is loaded alongside it.


    ### In-Memory Execution


    The payload remains encrypted until runtime. When the stealer is loaded into memory, it decrypts and executes—a technique that defeats detection mechanisms looking for malicious code on disk.


    ### Continuous Development


    BlackFog's analysis uncovered capabilities not listed in the public sales material, including:


  • LSASS dumping (extracting credentials from Windows authentication memory)
  • RunPE (running executables in-memory or from disk)
  • Keylogging (capturing typed credentials)
  • File managers (browsing and exfiltrating files)
  • Reverse shells (providing command execution)
  • Built-in Tor tunneling (anonymizing command-and-control traffic)

  • This suggests active development and feature expansion—the developers are continuously improving their product.


    ## Scope and Real-World Impact


    ### Who Gets Compromised?


    OnyxC2's focus on password managers, 2FA extension backups, FTP clients, and email accounts pushes it beyond consumer-grade threats. A small business's operations team, finance coordinator, or IT staff member with saved credentials in browsers becomes a gateway to:


  • Email account compromise
  • FTP/SFTP access to web servers
  • Business email and file systems
  • Cryptocurrency holdings and trading accounts
  • Backup authentication tokens that bypass password-reset protections

  • One infected workstation is effectively a standing access point into a person's working life.


    ### Detection Evasion Proven in the Wild


    BlackFog's testing is alarming: both delivery archives uploaded to VirusTotal came back clean initially, and the malicious component inside remained undetected when last checked on May 30, 2026. This real-world stealth is the feature that justifies the $250+ monthly rental price—it actually works.


    ## Implications for Organizations


    The democratization problem: Historically, sophisticated credential stealers required either purchasing from high-tier threat groups or possessing advanced malware development skills. OnyxC2 breaks that barrier. A criminal with no malware expertise can now rent professional-grade credential harvesting for the price of a few sandwiches per month. This dramatically expands the threat landscape.


    The persistence problem: Session cookies and authentication tokens mean compromised accounts remain exploitable even after password changes. Organizations that reset employee passwords after a breach may believe they've stopped the threat, but OnyxC2 has already harvested tokens that grant access independent of passwords.


    The insider-risk overlap: OnyxC2 is attractive to both external attackers seeking initial access and insider threats seeking to cover their tracks by blaming external compromise. The stealer's ability to operate silently for extended periods makes attribution and timeline reconstruction difficult.


    ## Recommendations for Defense


    Organizations should implement:


  • Browser isolation or containerization for high-risk users (finance, operations, executives)
  • Endpoint detection and response (EDR) focused on identifying unsigned DLL loads and suspicious process memory activity
  • Credential guard (Windows Defender Credential Guard) to protect LSASS memory
  • Browser extension audits quarterly, removing unnecessary or unknown extensions
  • Session timeout policies that force re-authentication, reducing cookie exploitation window
  • Network segmentation that limits lateral movement from a compromised workstation
  • 2FA on all critical accounts, with backup codes stored offline (not in browser vaults)
  • Monitoring for unusual cookie/session activity in email, cloud storage, and business systems

  • ---


    ## HackWire Analysis


    The OnyxC2 story reflects a critical shift in cybercriminal economics: the professionalization of previously specialized attacks. Stealer malware has existed for years, but charging $250 monthly with refund guarantees and ready-made lures represents a maturity threshold. These operators have moved from building tools for themselves to building tools for a market.


    What's particularly concerning is not that OnyxC2 exists, but that it's *successful*. The evasion is flawless—zero detections across 71 antivirus engines—because the developers understood defensive blind spots: legitimate signed applications, encrypted payloads, and in-memory execution. They've solved detection at a fundamental level, not just temporarily bypassed it.


    The threat also exposes a misconception in corporate security: password resets don't stop sophisticated breach recovery. If an attacker has harvested session cookies and authentication tokens (particularly for 2FA backup systems), a password reset is theater. The attacker still has access. Organizations measuring breach containment by "how many employees reset passwords" are missing the actual persistence vector.


    The real danger is the next logical step: once OnyxC2 exfiltrates email and FTP credentials, what stops an operator from setting up forwarding rules, stealing documents, or selling access to specialized breach buyers? A compromised workstation becomes a pivot point into corporate systems, and the evasion techniques keep it invisible for months. This isn't just credential theft; it's enterprise access brokerage for criminals without access brokers.


    Organizations should assume that if their staff use typical browsers and password managers, and if any of them received convincing phishing emails over the past six months, compromise is possible. The EDR stack becomes the difference between detection at 30 minutes versus 30 months.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Malware](https://www.hackwire.news/category/malware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)