Uptime Hamster: 21d 4h 54mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza onyx

onyx

2 incidentes 1 paises 0 sectores threat-actor KP Ultimo: 2026-06-29
Aliases: PLUTONIUM o Onyx Sleet en fuentes no verificadas, APT ONYXSLEET, apt-45, apt45, onyx sleet, silent chollima
Ver en IntelTracker → APTTrail →
Onyx is a ransomware group that first appeared in April 2022, operating with the primary motivation of financial profit through file encryption and data exfiltration for ransom. The group is notable for consistently employing double extortion tactics, threatening public release of sensitive victim data if ransom demands are not fulfilled. Onyx has shown an evolving operational posture, moving towards incorporating zero-day vulnerabilities into its campaigns and refining its attack methods to avoid detection.

Aliases del actor

PLUTONIUM o Onyx Sleet en fuentes no verificadasAPT ONYXSLEETapt-45apt45onyx sleetsilent chollima

Actores similares

apt-onyxsleetactor · 1Pearl Sleetapt · 0Silent Chollimaapt · 0Opal Sleetapt · 0Ruby Sleetapt · 0apt-c-01actor · 2apt-c-27actor · 2apt-45actor · 2apt-c-37actor · 1apt-c-23actor · 1

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
DLS / leak siteunknownransomware.anggipradana.comRansomware Group: onyx
DLS / leak siteunknownotx.alienvault.comAPT ONYXSLEET indicators and references
DLS / leak siteunknownwww.microsoft.comAPT ONYXSLEET indicators and references
Repositoriounknowngithub.comAPT ONYXSLEET indicators and references
DLS / leak siteunknownraw.githubusercontent.comAPT ONYXSLEET indicators and references
DLS / leak siteunknownotx.alienvault.comAPT ONYXSLEET indicators and references
DLS / onionofflinemrdxtxy6vqeqbmb4rvbvueh2kukb3e3mhu3wdothqn7242gztxyzycid.onionCTI.FYI
Tecnicas MITRE
T1070.004, T1486, T1059.001, T1047, T1566.001
Victimas
0
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (1)

Paises objetivo (OSINT)

BrazilGermanyEstoniaGuatemalaIndiaJapanKorea, Republic ofMexicoUnited States

Sectores objetivo (OSINT)

Construction of BuildingsFood ManufacturingSoftware PublishersEnterprises & HoldingManufacturingConstructionPublic AdministrationOil & GasBeverag & Tobacco ManufacturingEducational Services

URLs nuevas detectadas en IntelTracker

ransomware.anggipradana.com