Recovery Ransomware Services Onyx

ONYX RANSOMWARE
Professional Technical Threat Profile
Threat Classification : Ransomware / Destructive Ransomware
First Observed : April 2022
Platform : Microsoft Windows
Family/Origin : Based on Chaos Ransomware Builder v4
File Extension : .ampkcz
Ransom Note : readme.txt
Encryption : AES + RSA
Attack Model : Double Extortion
Severity : Critical
1. Overview
Onyx Ransomware is a ransomware operation first observed in April 2022. The malware is based on a modified version of Chaos Ransomware Builder v4 and employs a double-extortion approach, in which attackers may exfiltrate sensitive data and subsequently encrypt or destroy victim files to increase pressure for ransom payment.
Onyx has a particularly destructive characteristic that distinguishes it from conventional ransomware: certain files are not simply encrypted but may instead be overwritten with random or junk data.
2. File Encryption & Destruction
| File Condition | Onyx Behavior | Recovery Potential |
|---|---|---|
| < 2 MB | Encrypted using AES + RSA | Potentially decryptable |
| > 2 MB | May be overwritten with random/junk data | Generally not decryptable |
Files with .onynx | Renamed after processing | Requires further analysis |
This behavior is one of the most critical aspects of Onyx ransomware during recovery operations.
Files larger than approximately 2 MB that have been completely overwritten with random data are not merely encrypted files. Consequently, obtaining a decryptor does not necessarily mean that these files can be recovered.
3. Attack & Persistence Behavior
Reported Onyx capabilities include:
- File and Directory Discovery
- Targeting various user directories and file types
- Deletion of Volume Shadow Copies
- Deletion of backup catalogs
- Use of Registry RunOnce for persistence
- Creation of shortcuts in the Startup Folder
- Examination of mounted drives and potential propagation through accessible drives
- Modification of the system wallpaper as part of the attack impact
These activities correspond to several MITRE ATT&CK techniques, including:
- T1486 – Data Encrypted for Impact
- T1083 – File and Directory Discovery
- T1082 – System Information Discovery
- T1547.001 – Registry Run Keys / Startup Folder
4. Ransomware Identification Indicators
Primary Indicators
Ransomware Family : Onyx File Extension : .onyx Ransom Note : readme.txt Platform : Windows Encryption : AES + RSA Base : Chaos Ransomware
However, the presence of the **.onyx extension alone should not be considered sufficient evidence to conclusively identify an incident as Onyx ransomware.
Proper identification should include analysis of the ransom note, file structure, malware sample, file metadata, encryption characteristics, and other forensic indicators.
5. Recovery Assessment
Onyx should be classified as ransomware with significant destructive behavior.
Forensic and data-recovery investigations should prioritize the following sequence:
Encrypted File → File Size → File Signature/Header → Entropy → Encryption Pattern → Original File Structure → Backup/Snapshot → Deleted File & Filesystem Recovery
For files larger than 2 MB, investigators should not immediately assume that the files are simply encrypted and require a decryptor.
The first objective should be to determine whether the original data is still present on the storage media or whether it has been overwritten with random data.
If the original data has been completely overwritten, a conventional decryptor cannot reconstruct the original content. Recovery efforts should instead focus on alternative sources such as:
- Available backups
- Virtual machine snapshots
- Storage snapshots
- Deleted-file recovery
- Filesystem-level recovery
- Replicated or secondary copies
- Other surviving copies of the affected data
6. RRI Technical Classification
Recommended classification for the Recovery Ransomware Indonesia (RRI) ransomware database :
ONYX — Destructive Ransomware / Chaos-Based Variant
Primary Impact : Data Encryption + Data Destruction
Recovery Difficulty : Very High
Decryptor Dependency : Partial
Files >2 MB : Potentially permanently destroyed
Recommended Approach : Forensic Analysis Before Decryption Attempt
Important : Not all files affected by Onyx necessarily have the same condition. Analysis of both original and affected file samples is essential before determining whether recovery through a decryptor is technically feasible.






