Oyster, also known as Broomstick, CleanUpLoader, and OysterLoader, is a Windows malware family first publicly identified in 2023 and commonly characterized as a backdoor or loader used to establish persistent remote access and deliver follow-on payloads. It has been repeatedly observed in malvertising and SEO-poisoning campaigns that impersonate legitimate software, including Microsoft Teams, Google Meet, PuTTY, WinSCP, KeePass, Google Chrome, and other widely used tools. Distribution has also been tied to trojanized installers and fake update lures, including campaigns that used fraudulently code-signed binaries.
Oyster is designed to minimize forensic visibility by loading multiple DLL stages directly into memory using shellcode-based reflective DLL injection and related in-memory execution techniques. Reported samples dynamically resolve Windows APIs at runtime and include anti-debugging measures. Multi-stage infections commonly begin with a fake installer that launches an initial DLL, retrieves additional stages from command-and-control infrastructure, and ultimately loads a final payload that provides persistent remote access. Observed persistence mechanisms include scheduled tasks that repeatedly invoke malicious DLL exports through rundll32.exe, allowing the malware to survive reboots and maintain execution.
The malware supports command-and-control communications over HTTP or HTTPS, victim registration, remote command execution, reconnaissance, and deployment of additional malware. Intrusions involving Oyster have shown hands-on-keyboard activity, use of cmd.exe and PowerShell for discovery, and follow-on delivery of malware such as Vidar, Lumma Stealer, Rhadamanthys, Hijack Loader, and Supper. In multiple investigations, Oyster infections preceded broader post-compromise activity including credential theft, access-token theft, Kerberoasting, and eventual ransomware deployment.
Oyster has been associated with financially motivated intrusion activity targeting corporate environments and has been linked in reporting to ransomware ecosystems including Rhysida and clusters overlapping with Vanilla Tempest or Rapid Brigantine. It has also appeared in campaigns supported by malware-signing services that supplied fraudulent certificates to make malicious installers appear trustworthy. Victims have included enterprise users across sectors, with observed lures particularly focused on business software and collaboration tools to gain initial access into corporate networks.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ANALYST NOTE: Interestingly, Oyster malware (which is likely related with the threat actor behind Lactrodectus) uses similar API endpoints for C2 communication.
The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers.
BlueVoyant assesses that Lorem Ipsum Loader is most likely a parallel or successor loader within Rapid Brigantine's toolkit rather than the same family Microsoft tracks as Oyster.
While the example campaign described in this section delivered Vidar Stealer, we have also observed this campaign distributing Lumma Stealer, Hijack Loader, and Oyster.
The lawsuit targets Fox Tempest’s infrastructure and also names Vanilla Tempest as a co-conspirator, a prominent ransomware group that used the service to deploy malware like Oyster, Lumma Stealer, and Vidar, and ransomware, including Rhysida, in multiple recent cyberattacks.
The service had been used to sign and distribute malware, including Rhysida ransomware, Oyster, Lumma Stealer, and Vidar, making malicious software appear legitimate and easier to deliver at scale.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
It is primarily distributed via malvertising campaigns that deceive users into downloading trojanized installers for legitimate software, such as PuTTY, KeePass, WinSCP, Google Chrome, or Microsoft Teams.
In October 2025, MSTIC publicly attributed and disrupted a Rapid Brigantine campaign distributing fake MSTeamsSetup.exe files hosted on Teams-themed malicious domains ... driven by SEO poisoning and malvertising.
Further analysis revealed that Fox Tempest expanded its offerings earlier this year by providing customers with pre-configured virtual machines hosted through Cloudzy infrastructure. Users could upload malware to these systems and receive digitally signed binaries generated through certificates controlled by the group.
Analysis of the redirection chain determined that the attack likely originated from free movie streaming sites. Infections on such sites typically begin when users interact with embedded movie players or click popups.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
Opening the malicious attachment executes an HTML file with embedded JavaScript that is highly likely generated by an LLM. This script is designed to download and execute additional payloads
The ZIP file contains an LNK file that, when executed, runs a PowerShell script... likely generated using an LLM.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
In certain variants, the second-stage DLL drops an executable on disk. This executable is then launched, and the final third-stage DLL is injected into its memory.
Each function within DllMain contains embedded shellcode fragments. As functions execute in a predetermined order, these fragments are progressively copied into a allocated memory region.
the loader resolves essential Windows API functions—including LoadLibraryA, GetProcAddress, VirtualProtect, and InternetOpen—via dynamic resolution.
The fake installer (masquerading as legitimate software) contains a sequence of functions that embed shellcode.
In certain variants, the second-stage DLL drops an executable on disk. This executable is then launched, and the final third-stage DLL is injected into its memory.
the North Koreans added three custom modules: browserlogin... companywallet... and cleanup (anti-forensic removal of workspace artifacts).
File Hash (SHA-256) 16474e9e4773fbc1e0b48a5025fad31b7f084b1beffb9a42687b4d01979885fe Dave-crypted IceNova
This second-stage payload is subsequently loaded using rundll32.exe (via exported function execution) and establishes persistence by creating a scheduled task that periodically re-executes the payload.
149 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
102 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison point for similar C2 API endpoint usage.
Mentioned only as a comparison point for similar C2 API endpoint usage.
A loader whose operators leveraged the illicit malware-signing service to obtain signed malicious software.
A backdoor mentioned as part of a similar Teams-themed campaign, not the primary malware in this report.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.