OnyxC2 Malware-as-a-Service Offers Enterprise-Grade Data Theft

2026-06-11T14:51:43Z68b91177ead8bb454774bbdcb8b4a8c4ab234e9d8df874134751c29bf9d5b6e7
MaaSai-wormsbitlocker-bypasschaotic-eclipsecisa-kevcve-2025-8088cve-2026-25089dll-sideloadingfortinetfortisandboxiotjdy-botnetmalwareonyxc2patch-tuesdayrogueplanetstealertchap-breachwinrarzero-day

What happened

Multiple high-impact threats and zero-days disclosed: OnyxC2 emerges as a Malware‑as‑a‑Service stealer (DLL sideloading, encrypted payloads, HVNC) targeting 210+ apps; Chaotic Eclipse published two powerful Microsoft Defender/BitLocker exploits (RoguePlanet PoC and GreatXML) that can yield SYSTEM on fully patched or recovery-mode Windows systems; Fortinet patched a critical FortiSandbox OS command‑injection (CVE-2026-25089, CVSS 9.8); and research/demo activity includes autonomous “AI worms.” Other notable issues: JDY botnet activity targeting military networks and IoT/SOHO devices, ongoing EX

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
68b91177ead8bb454774bbdcb8b4a8c4ab234e9d8df874134751c29bf9d5b6e7
Enrichment time
2026-06-11T14:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.