The Edgecution malware exploits the Chrome Native Messaging protocol to enable communication between browser extensions and native desktop applications.
The Windows variants, WIN_DRV and WIN_PLUS, retain the core architecture of their Linux predecessor, including command-and-control (C2) protocols and encryption methods.
Kaspersky researchers have identified that malicious actors are exploiting the Steam Workshop platform, specifically through the Wallpaper Engine application, to distribute malware.
The attackers send emails designed to raise alarm about potential account compromise and OTP abuse, tricking recipients into opening an attachment, according to the Genians Security Center.
OnyxC2 is being sold on cybercrime forums for as little as $250 per month, with developers offering refunds if their builds are detected, highlighting confidence in its evasion capabilities.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.