Inside the Onyx C2 Ransomware Business Model
For $250 a month, anyone with zero skill can now run a ransomware operation — keylogging, RATs, session cookie theft, and full attacker support included. Dr. Darren Williams, Founder and CEO of BlackFog, returns to Techstrong TV with Alan Shimel to unpack Onyx C2, the new ransomware-as-a-service model his team has tracked actively in the wild 254 times and counting. Drawing on his PhD in pharmacology and 25+ years of building category-defining tech, Darren explains why every cybersecurity strategy that focuses only on the front door is destined to fail — and why anti data exfiltration (ADX), pioneered by BlackFog, has become the resiliency layer modern enterprises can’t ignore. He and Alan also dig into why reimaging a compromised endpoint no longer works when session cookies and MFA keys have already been stolen, and what a holistic, biology-inspired approach to security really looks like.
Transcript
Hey everyone. Welcome back here to Techstrong TV. I'm happy to introduce you to my next guest.
He's Dr. Darren Williams. He's been on with us before.
Here he is, the CEO, co-founder of Black Fog. com. Darren, welcome back to Techstrong TV.
It's great to have you on. Great to be here. Thanks for having me, Alan.
Darren, I'm going to bet that not everyone watching this today saw your last appearance on Techstrong TV, and are familiar with your interesting story, as well as the Black Fog story. So if you don't mind, I'm going to ask you to repeat a little bit and tell people- Sure ... a little bit about yourself, and then we'll jump into Black Fog.
Yeah, no problems. Well, as you said, I'm the founder and CEO of Black Fog. We established ourselves around 2015.
The whole premise of the idea back then was pretty simple, that there was so many products out there that all did the same thing, and everybody is always so focused on watching the front door and detection. Everyone forgets that the whole point of ransomware is actually about data leakage, and it's all about data exfiltration effectively. And so we thought, "Wow, that's really interesting.
" Because it's not been tackled effectively. All these existing solutions, firewalls, DLP solutions, they don't really work that well. So we sort of invented that technology and we call it ADX, anti-data exfiltration.
And we've been pretty much perfecting that technology for the last 10 years or so. Absolutely. And another 10-year overnight sensation, right?
Well, exactly right. People think- So many products out there ... the startup world is such a, these companies, they do a seed round and the next thing you know, they're selling for billions.
Well, exactly. But Darren, this Black Fog, even though you've been at it now over 10 years- Mm-hmm ... it's not your first startup either, though.
You've had- Right ... you've dipped your hand in, or dipped your toe in the water before. Give us a little of that background.
Yeah. So, initially we actually started, well, I guess it was back in the late '90s now, before the last boom and crash actually, quite interesting. " And we had a technology which is effectively like Google Analytics is today.
So we basically were one of the... Google Analytics, I don't know if many of your listeners know, but that was originally Urchin Software based out of San Diego. I remember that.
Well, we were the competing product with those guys, and it's interesting, at about the same time we were acquired, Urchin was acquired by Google. So we got acquired by Quest Software back in the day. Mm-hmm.
And, so that really, I spent a little bit of time at Quest Software after that, and then, after about a couple of years, I think it was only maybe even a year there, got the itching to do something new. Once you do a transition, it's really hard. So started a new company, and that was Lifetime Software.
And that genesis of that idea was interesting in that it came from, we saw all the inefficiencies going on at Quest Software, and one of the things that was actually happening back then was the development of CRM, Siebel Systems, et cetera- Right ... and all these support systems, and they were so expensive. I think they spent like 500, $600,000 on a support system, and it's like, dude, if they are willing to spend $500,000 on a support system and it's not even that great, because we were interacting with it, imagine what it would be like if we developed a really good one.
So we invented Lifetime Software, which was a product about customer service and support, which became service management, which was eventually acquired by Absolute Software, which is a- Mm-hmm ... Canadian-based company who had a really good- Yeah, no, I'm familiar with Absolute. I've actually had them here on Techstrong TV.
Yeah. Great technology that they had there, and that's what gave us the impetus for Black Fog, in the end. It's funny you mention Urchin.
So, I started, my very first company was a web hosting company in like 1996, '97. Yep. It was even before there was Urchin, quite frankly.
There was- Oh, really? Yeah. You go back further than I do.
I remember when Urchin launched, I knew, I think it was two or three co-founders. Right. I knew the guys.
Interesting. Oh, wow. So I had started a hosting company before we called it hosting.
I thought I was a digital landlord. And every time I needed more property, I'd buy another hard drive. Got it.
These are days of brochure where websites that- Yeah ... I could put 1,000 websites on a web server, and different things. Right.
Yeah, for sure. Well done. But then, of course, Google, they bought Urchin, they named it Google Analytics, and it did become the de facto standard for stat packages anyway, though- Exactly.
Makes a lot of sense now. People take it for granted how things are today. Yeah.
You forget the genesis of a lot of these products and solutions. And I didn't think Urchin was all that, I'll be honest with you. No.
No, I thought our product was better. It wasn't the best product in the market, but- I was annoyed we didn't get acquired by Google instead of Urchin. Exactly.
We may not have had this conversation. Yeah, exactly right. But you'd be home counting your Google stocks.
Exactly. Anyway. But let's focus in on Black Fog, though.
Sure. And 10 years ago you launched it. The mission is the mission.
Yes. How has it changed? A lot of water under the bridge since 2015.
Yeah, a lot. So you got to remember back at 2000. So the genesis of the idea was actually because at Absolute Software, they have a really interesting technology, which actually is like a sort of modern ransomware, and the idea was that you stole a computer, and it would brick the computer, and you'd have to return it.
And then, you know what criminals do. " But it was persistent in the BIOS, and so it would always come back again, so you couldn't get around it. Now, fast-forward to 2015 with modern ransomware, we realized that people were buying the product because they were effectively a pseudo-insurance policy effectively.
You got to remember, if we go backwards, laptops were really, really expensive, even PCs. $4,000, $5,000. Big asset, big CapEx expenditure.
Yep. And so people were saying, "Well, if I just buy that product, which is only a few dollars a node, who cares? " So it was a replacement cost.
But the whole concept was based around the expensive nature of the asset. Now, in 2007, of course, with the release of the iPhone, that changed the world as we know it today, and all the asset prices came down dramatically, so no one really needed that level of software. And it also reframed our thought process, and we thought, "You know, it's actually never been about the hardware.
" And everyone loses sight of that because the propeller heads are always focusing on hardware and devices and infrastructure. It's actually about the data. It's always been about the data, but no one's really solved that problem.
" So we spent four years really developing the tech in stealth mode, and really 2019, '20 is when we sort of launched, around the COVID time, actually. But it was a privacy solution originally, and then we realized that everyone talks a great game about privacy, but actually no one's got any money to pay for it or cares enough to actually spend money on it. No.
All the money sits actually in the IT department. And so actually our CMO and sort of co-founder, Brenda, she said, "It's a great technology. " And she said, "There's this ransomware thing I'm starting to see out there.
9% effective at stopping ransomware because if you think about what data exfiltration is, it's the back channel. Like it's the back door of the building. So you can block the front door all day long, but if they're already in and they're stealing data out the back door, that's what it's all about.
And so we found out it was really effective, spun the technology, and then we invented ADX, or Anti-Data Exfiltration, and that's where the product really just took off. And all of a sudden, all the CISOs wanted it, and it plugged a hole that existed that still to this day a lot of people don't even think about. Because it's easy to think about defense, right?
And endpoint products, EDR products, that's all they do, right? They're detection, detection, detection. And with modern ransomware and modern polymorphic fingerprintless applications, they don't really work that well.
But you can always stop the data moving out. Very hard to do the detection. And in fact, most, like this Onyx thing that we're going to talk about, that's all about getting around the detection and the EDR products.
Right. It's 98% effective against getting through every EDR product that exists on the market. So what you described here, Darren, I've been in security 25 years myself.
It's really about the move to resilience and resiliency as well. For so long, we put all of our eggs in the detection, prevention basket. Right.
We're going to find that attacker. We're going to block that attack. And we never planned for what happens if we didn't find that attacker.
We didn't block that attacker. Right. And that's more common than you would think.
You're exactly right. I mean, it's pretty much- Yeah ... you know they train all of these tools, like Onyx is a great example, right?
So the Onyx trains against all of the existing cybersecurity EDR tools. So it gets through automatically, right? And it's a game you sort of can't win in a way.
So what can we do? And so my PhD is actually in pharmacology, so we do drug development, and we're all about holistic detection and development of drugs. So when you target a drug, like COVID's a great example, you don't just do the cell membrane, which is the attack vector to get in.
You're hitting the mitochondria, the DNA replication cycle, you're doing the whole body base. You think about things holistically, and I don't think cybersecurity does that very well. And so we're- No, that was never our strength, let's be honest.
Right. It's really point-based. It's like symptomatic relief is the way I think about it from a medical perspective.
It's like- Mm-hmm ... yeah, I can stop your runny nose, Alan, and I can stop your aches and pains, but the virus is still kicking in, in your body. So let's kill the virus.
Right. And so when it comes to extortion and ransomware, we're all about let's just stop the problem by if they don't have the data They can't extort you. Absolutely.
You don't have to report anything. So that's how we think about the problem. So just a different approach.
com is the website as it says on your background. Yep. So people who are interested in this and want to dig in more can dig in more.
Sure. Darren, I wanted to segue into our topic of discussion today while we have time. Uh-huh.
You guys, part of the mission is the research too, right? Finding- It's a big part of it, yeah ... finding new vectors, new attack methods, et cetera.
Right. You guys recently came up with something new. Yeah, we did, the Onyx C2.
Tell us. Yeah. So the Onyx C2 is the latest attack channel that we're actually seeing.
Now, what's interesting about this is we've known about this earlier in the year, but didn't really see it active. So it's basically a new form of malware, which is not about the technique per se, but it's about the business model. And that business model is you could sign up and subscribe to this service, which is basically a website, which includes a RAT, it includes key logging, it includes all of the tools you need to extract session cookies and all of the credentials from that machine.
Now, why is that important? Well, first of all, lowers the barrier to entry. It's truly a business now.
For $250 a month, I can have no skill at all. I can go to Alan, buy Onyx C2, and he will support me like a normal organization will, which is- Oh, good ... which is incredible.
So people in cybersecurity know this. Mm-hmm. People not in cybersecurity, it's this revelation that the bad guys are pretty well organized, and there's strategy.
Very well. There's levels. This person extracts personal data.
The next level, they're only interested in credit card data. The next level may be interested just in a Social Security number. Yep.
This one just makes RATs. So it's a rich ecosystem- It really is ... that's very well organized and very well-financed.
Very well-financed, and it's also very well distributed. As you look at the FBI, and we work with the FBI for trying to give them information to help them take down a lot of these guys. It's really interesting because it provided all of the key things you need to be a great attacker for $250 a month.
And one of the cool things about it, I guess it is cool, but from a technical perspective, but they extract all the session cookies and IDs. Now, if you think about what you said earlier about resiliency, one of the common techniques that your IT department's going to do is let's just wipe the machine, re-image it, and we're good to go. Well, with this new approach, if you've got the session cookies and your multi-factor authentication keys, it doesn't matter how many times you re-image it, I already have all the secret sauces to get back in again.
So this is where I think things have changed, and we have seen it actively deployed and being utilized now, which I think is different to some of the other vectors which are maybe academic. Mm. This is actually in the wild and used, I think it's 254 times we counted so far.
So it's actually quite extensively used. Absolutely. Darren, I'm just looking at our notes here, and I want to make sure I quote everything.
Yeah. com and look at your services. " Well, you've got to detect, right?
Right. You've got to detect that fact that, let's say you're watching the back door. You've got to watch what's leaving the building all of the time, and you can even use your firewalls.
Let's just think about paid internet, go to us. We're doing all the research, sure. But ultimately, it's all about the data leaving the device.
So what are you doing as a business that is actually monitoring that? And you can monitor that. There are tools around that.
You can use your firewall. There are lots of things you can do. But if you're not watching the back door, you're missing a really important vector.
Absolutely. And I think that's the key. And taking it from physical security, you just don't put the alarm on your front door.
Exactly right. Great analogy. Exactly right.
Absolutely. That's how we think about it, too. Anyway, Darren, we've got to jump, but I want to thank you for coming on.
Hopefully, we'll see you soon again. You bet. I love what you're doing with Black Fog.
Keep up the great work, my friend. Great. Thank you, Alan.
I know sometimes it's thankless, but there's hard work that needs to get done. Right. Thanks, Alan.
Really pleasure. All righty. Dr.
Darren Williams, founder, CEO of Black Fog here on Techstrong TV. We're going to take a break. We'll be right back.