Ransomware Group intelligence
Onyx
InactiveTrack Onyx with 28 published victims and 1 known leak locations in a single intelligence view.
Overview
Onyx is tracked by Breach House as a ransomware group with 28 published victims.
Brazil is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 1h ago | mrdxtxy6vqeqbmb4rvbvueh2kukb3e3mhu3wdothqn7242gztxyzycid.onion |
Top Activity Sectors (5)
Typical Attacks (8)
▼MITRE ATT&CK does not currently catalogue Onyx, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: onyx executes malicious commands via PowerShell scripts to spread payloads and manipulate system behavior.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
What they do: onyx modifies registry run keys to ensure persistence and automatic execution on reboot.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: onyx disables security tools like antivirus software to evade detection during the attack chain.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1070.004 File Deletion Stealth
What they do: onyx deletes Volume Shadow Copies and backup directories via command-line tools to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1018 Remote System Discovery Discovery
What they do: onyx performs remote system discovery to map the network and locate high-value targets.
What that means: Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
-
T1135 Network Share Discovery Discovery
What they do: onyx discovers network shares using native API calls to identify additional victims for lateral movement.
What that means: Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement.
-
T1486 Data Encrypted for Impact Impact
What they do: onyx encrypts victim files using custom ransomware binaries to maximize impact and extortion leverage.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: onyx invokes system recovery inhibition commands to lock down infrastructure and hinder remediation.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (28)
Search, filter and paginate the victim timeline for Onyx. Showing 1–28 of 28.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | www.artisticstairs.com id4639 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.wayan.com.mx id4638 View details | Mexico | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | www.candcfarmsupply.com id4637 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.ackermanplumbinginc.com id4636 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.semaphorehq.com id4635 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.baltholding.eu id4634 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.pacmaritime.com id4633 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.waynefamilypractice.com id4632 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.advantagedirectcare.com id4631 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.cucafresca.com.br id4630 View details | Brazil | Other | — | |
|
No additional victim description available. |
|||||
| Ransomware | www.arisaseguros.com id4629 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.jaspercountysheriffoffice.com id4628 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.minex.gob.gt id4627 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | www.projectredirectdc.org id4626 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ministerio de Relaciones Exteriores id4249 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Borough of Union Beach id3908 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | ARISA CORREDORES DE SEGUROS id3891 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | CUCA FRESCA id3870 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | WAYAN NATURAL WEAR id3869 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Artistic Stairs & Railings id3868 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Baltholding OÃ id3866 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Jasper County Sheriff's Office id3322 View details | Public Sector | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Pacific Maritime Industries Corp. id3310 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | WAYNE FAMILY PRACTICE, ASSOC., P.C. id3309 View details | Communication / Marketing | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Advantage Direct Care id3308 View details | Other | — | ||
|
No additional victim description available. |
|||||
| Ransomware | C&C FARMERSâ SUPPLY CORP id3307 View details | Agriculture / Food | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Semaphore Solutions Inc id3306 View details | Services | — | ||
|
No additional victim description available. |
|||||
| Ransomware | Ackerman Plumbing Inc id3305 View details | Services | — | ||
|
No additional victim description available. |
|||||