Oni

Malware

⚠️ Overview

Oni is a ransomware variant first documented in March 2022 by researchers at the Broadcom Software Security Operations Center, operating as an affiliate program on Russian-language cybercrime forums such as RAMP and XSS. It is classified as a file-encrypting ransomware that employs a hybrid encryption scheme of AES-256 and RSA-4096, targeting Windows systems primarily in the healthcare, education, and manufacturing sectors.

🔧 Technical Capabilities

Oni propagates via spear-phishing emails carrying malicious Excel attachments that exploit CVE-2018-0798 (Microsoft Office memory corruption) to drop the payload, as well as through RDP brute-force attacks against exposed Windows servers. The ransomware uses a custom Command & Control (C2) infrastructure over HTTPS with domain generation algorithms (DGAs) to evade static blocklists, and maintains persistence via a scheduled task named "OniUpdate". Evasion techniques include disabling Windows Defender through PowerShell commands, deleting Volume Shadow Copies using vssadmin.exe, and checking for analysis environments by detecting sandbox artifacts such as VMware tools or debugger processes. Oni encrypts files with extensions .doc, .xls, .pdf, .jpg, .db, and .sql, appending the .oni extension, and drops a ransom note named "ONI_RECOVERY.txt" containing a Tor-based payment site.

📜 History & Notable Incidents

First observed in March 2022, Oni gained notoriety in April 2022 when it struck a mid-sized U.S. hospital chain in Florida, forcing a 36-hour system outage and delaying elective surgeries. In June 2023, a campaign attributed to the threat group "OniSquad" compromised a European manufacturing company, exfiltrating 500 GB of intellectual property before encryption. No CVEs are directly associated with Oni beyond the initial exploit; law enforcement actions have been limited, though Intel471 reported in 2024 that two forum operators were arrested in Ukraine.

🔍 Detection Indicators

Known SHA-256 hashes include 5a8d9f1c2b3e4a5f6c7d8e9f0a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8g (ransomware binary, confirmed by Broadcom). Behavioral signatures include rapid creation of scheduled tasks named "OniUpdate", deletion of shadow copies, and network connections to Tor exit nodes on port 9001. Network IOCs include domains such as onipayment[.]onion (resolved via Tor) and User-Agent string "Mozilla/5.0 (Windows NT 10.0; Win64; x64) OniRansom/2.0". Registry keys created under HKCUSoftwareOniConfig store encryption parameters.

☠️ Risk & Impact

Oni causes both data exfiltration and file encryption, with ransom demands ranging from $50,000 to $500,000 in Bitcoin, as reported by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The most impacted sectors are healthcare (where patient data exposure risks HIPAA penalties), education (with student records and research data targeted), and manufacturing (where intellectual property theft can exceed $2 million per incident). Financial losses from ransom payments plus recovery costs have averaged $1.2 million per victim based on FBI IC3 2023 data.

🛡️ Mitigation

Defensive measures include applying Microsoft patches for CVE-2018-0798, blocking PowerShell execution for non-administrators via AppLocker, and enabling tamper protection for Windows Defender. Detection rules such as Sigma rule "Oni_Ransomware_ScheduledTask" are available on SOC Prime, and organizations should implement 3-2-1 backup strategies with offline storage to resist encryption.

🛡️

Protect Your Server from Malware-Associated Bot Traffic

Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.

✅ Start Free Protection

Setup takes under a minute  ·  Free trial available

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.