OnyxC2 stealer malware is being sold to cybercriminals as a subscription service

A newly analyzed malware service called OnyxC2 is being rented to criminals for as little as $250 a month, giving buyers a ready-made tool to steal passwords, cookies, wallet data, and other sensitive information from infected Windows systems. BlackFog says the stealer targets about 210 applications and browser extensions across browsers, password managers, cryptocurrency wallets, FTP and email clients, and some 2FA extensions, and uses encrypted payloads, DLL sideloading, in-memory execution, HVNC hidden remote control, keylogging, reverse proxying, and LSASS dumping to evade detection and maintain access.
Why it matters: This lowers the barrier for account theft and follow-on fraud or intrusion by packaging advanced credential-stealing and remote-access features as a commercial criminal product. Organizations and consumers should treat it as a high-risk infostealer threat: watch for suspicious installers, strengthen endpoint detection, and rotate credentials and session tokens if infection is suspected.

Sources

OnyxC2 Stealer Offers Cybercriminals Enterprise-Grade Theft for $250 a Month
Kevin Townsend 2026.06.11 100% relevant
This article appears to be the establishing report for a distinct malware threat centered on the OnyxC2 stealer's criminal sale, capabilities, and delivery techniques, not an update to an already tracked event.
← Back to all stories