logo

OnyxC2 Stealer Uses Cloudflare-Fronted C2 to Exfiltrate Browser Data and Credentials

ID: 14f555bb-8577-5b90-8d6d-9c3d68ddaa3e

STIX ID: report--14f555bb-8577-5b90-8d6d-9c3d68ddaa3e

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Mayura Kathir

...
...

A commercial-grade information stealer called OnyxC2 has been marketed on cybercrime forums offering a web control panel, payload builder, and subscription pricing; it harvests browser-stored credentials, 2FA extensions, and crypto wallets, uses signed executable DLL sideloading and Cloudflare-fronted C2 communications to evade detection, and is distributed via password-protected archives and fake installers — the report includes technical analysis, mitigation guidance, and IOCs (domains, IPs, SHA-256 hashes, and C2 endpoint paths).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.