Onyx is a ransomware group that emerged in April 2022, primarily motivated by financial gain through extortion operations targeting organizations across North and South America. The group's country of origin and potential affiliations with other ransomware operations remain undetermined based on publicly available threat intelligence. Onyx has demonstrated a preference for targeting government and transportation sector entities, with their attack methodology and technical capabilities including initial access vectors, encryption methods, and data exfiltration practices not comprehensively documented in open-source intelligence reports from major cybersecurity firms or government agencies. The group has compromised 28 known victims, with the majority of their operations concentrated in the United States, Brazil, and Mexico, suggesting either a geographic targeting preference or regional access capabilities. Due to Onyx being a relatively smaller ransomware operation with limited public documentation from established threat intelligence sources like CISA, FBI, or major security research organizations, detailed information about specific notable campaigns, ransom demands, or high-profile victim organizations has not been extensively reported in public threat assessments. The current operational status of the Onyx ransomware group remains unclear based on available open-source intelligence reporting. The group has been linked to 28 public disclosures across our corpus. First observed on a leak site on April 29, 2022; most recent post January 2, 2023. The operation is currently inactive.
How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.