OnyxC2 Stealer Uses Cloudflare-Fronted C2 to Exfiltrate Browser Data and Credentials
ID: 14f555bb-8577-5b90-8d6d-9c3d68ddaa3e
STIX ID: report--14f555bb-8577-5b90-8d6d-9c3d68ddaa3e
Feed Name: GBHackers
A commercial-grade information stealer called OnyxC2 has been marketed on cybercrime forums offering a web control panel, payload builder, and subscription pricing; it harvests browser-stored credentials, 2FA extensions, and crypto wallets, uses signed executable DLL sideloading and Cloudflare-fronted C2 communications to evade detection, and is distributed via password-protected archives and fake installers — the report includes technical analysis, mitigation guidance, and IOCs (domains, IPs, SHA-256 hashes, and C2 endpoint paths).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
