Onyx is a ransomware group first observed in April 2022, based on the Chaos ransomware builder, that is notably destructive — files larger than 2MB are overwritten with random data rather than encrypted, making recovery impossible even after ransom payment — claiming approximately 13 victims across six countries. Known victims: 28
Objectives
Executive Summary
The Onyx ransomware group, first seen in April 2022, is a medium-sophistication criminal actor primarily motivated by organizational gain through ransomware and financial gain. Notably destructive, Onyx targets multiple sectors and countries, claiming around 28 victims, with a modus operandi that includes overwriting large files with random data, rendering recovery impossible. This behavior signifies a dangerous and malicious actor in the cybercrime landscape.
Goals & Targeting
Onyx's strategic objectives are centered around achieving financial gain through ransomware campaigns. The group targets organizations in multiple sectors and countries, likely seeking to maximize their financial returns by exploiting vulnerabilities wherever they are found. Their targeting profile suggests a focus on ease of exploitation and potential payout, with no specific preference for certain sectors or geographic locations, indicating a purely opportunistic approach to their attacks.
Enhanced Description
The operational tempo and victimology of Onyx suggest a focus on exploiting vulnerabilities and weaknesses in organizations' security postures. Given the global reach of their operations, it is imperative for organizations across various sectors to be vigilant and to implement robust security measures to protect against ransomware attacks. The lack of specific sectors or countries targeted by Onyx implies a more opportunistic approach, where any organization with vulnerable systems could potentially be a target.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Onyx's campaign patterns indicate a rapid operational tempo, with the group quickly exploiting vulnerabilities and demanding ransom. Their operations have been noted across multiple countries, suggesting a well-coordinated effort. Notable past operations include the compromise of approximately 28 victims, with the group's destructive approach leading to significant disruption. The group's use of the Chaos ransomware builder and their data overwrite tactic signify a dangerous and evolving threat landscape.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the available data on Onyx is moderate, based on the known victims and the group's observed tactics, techniques, and procedures (TTPs). However, there are information gaps regarding the group's full capabilities, internal structure, and long-term objectives. Further intelligence gathering and analysis are required to fully understand Onyx's potential and to predict their future activities accurately.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
2
IOCs
0
Observed Data
0
Tactics