Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

Onyx is a ransomware group first observed in April 2022, based on the Chaos ransomware builder, that is notably destructive — files larger than 2MB are overwritten with random data rather than encrypted, making recovery impossible even after ransom payment — claiming approximately 13 victims across six countries. Known victims: 28

Goals & Targeting

Objectives

Ransomware
Financial Gain

AI Analysis

· 2 weeks ago

Executive Summary

The Onyx ransomware group, first seen in April 2022, is a medium-sophistication criminal actor primarily motivated by organizational gain through ransomware and financial gain. Notably destructive, Onyx targets multiple sectors and countries, claiming around 28 victims, with a modus operandi that includes overwriting large files with random data, rendering recovery impossible. This behavior signifies a dangerous and malicious actor in the cybercrime landscape.

Goals & Targeting

Onyx's strategic objectives are centered around achieving financial gain through ransomware campaigns. The group targets organizations in multiple sectors and countries, likely seeking to maximize their financial returns by exploiting vulnerabilities wherever they are found. Their targeting profile suggests a focus on ease of exploitation and potential payout, with no specific preference for certain sectors or geographic locations, indicating a purely opportunistic approach to their attacks.

Enhanced Description

The operational tempo and victimology of Onyx suggest a focus on exploiting vulnerabilities and weaknesses in organizations' security postures. Given the global reach of their operations, it is imperative for organizations across various sectors to be vigilant and to implement robust security measures to protect against ransomware attacks. The lack of specific sectors or countries targeted by Onyx implies a more opportunistic approach, where any organization with vulnerable systems could potentially be a target.

Key Capabilities

  • Ransomware deployment
  • Data overwrite and destruction
  • Utilization of third-party malware builders
  • Potential for social engineering and phishing

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Chaos ransomware builder
Potential use of custom or other off-the-shelf malware

Campaigns & Victims

Onyx's campaign patterns indicate a rapid operational tempo, with the group quickly exploiting vulnerabilities and demanding ransom. Their operations have been noted across multiple countries, suggesting a well-coordinated effort. Notable past operations include the compromise of approximately 28 victims, with the group's destructive approach leading to significant disruption. The group's use of the Chaos ransomware builder and their data overwrite tactic signify a dangerous and evolving threat landscape.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • Potential use of exploit kits for initial access
  • C2 communication over non-standard ports
  • Use of temporary or disposable email addresses for ransom demands

Recommended Actions

  • Implement robust email filtering to block phishing attempts
  • Regularly update and patch all software and systems
  • Use anti-ransomware solutions and ensure regular backups are stored securely offline
  • Conduct regular security audits and vulnerability assessments

Suggested Tags

Ransomware
Criminal
Destructive Malware

Confidence Assessment

The confidence in the available data on Onyx is moderate, based on the known victims and the group's observed tactics, techniques, and procedures (TTPs). However, there are information gaps regarding the group's full capabilities, internal structure, and long-term objectives. Further intelligence gathering and analysis are required to fully understand Onyx's potential and to predict their future activities accurately.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

2

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware

Details

Type
Criminal
Sophistication
Medium
Primary Motivation
Organizational gain
Confidence
80%
First Seen
Apr 29, 2022
Last Seen
Nov 21, 2022
Added
May 4, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.