Oyster, also known as Broomstick, CleanUpLoader, and OysterLoader, is a C++-based Windows backdoor and loader first identified in September 2023. It provides persistent remote access, command execution, and delivery of additional malware, serving as an initial foothold in corporate networks and human-operated ransomware intrusion chains.
Oyster is commonly distributed through malvertising and SEO-poisoned search results that lead to fraudulent download pages offering trojanized installers for legitimate software, including Microsoft Teams, Google Meet, PuTTY, WinSCP, KeePass, Chrome, and Dropbox. Distribution has also used phishing emails containing password-protected archives with malicious shortcuts that launch PowerShell delivery scripts. Malicious installers may carry abused code-signing certificates to appear trustworthy; Oyster operators have used the Fox Tempest malware-signing service.
Its multistage execution chains retrieve and load malicious DLLs, using shellcode-based reflective loading and, in some variants, process injection to execute payloads in memory. Observed delivery chains also use AutoIt loaders and DLL sideloading. Anti-debugging checks, dynamically resolved Windows APIs, and reconstructed obfuscated shellcode hinder analysis and detection. Oyster establishes persistence through scheduled tasks that repeatedly execute its DLL payloads using Windows utilities. It communicates with attacker-controlled servers over HTTP or TLS to register infected hosts, receive commands, and retrieve subsequent stages.
Oyster enables hands-on-keyboard activity, reconnaissance, and follow-on payload deployment. It has been used by Rhysida-associated operators, including Vanilla Tempest, and observed in intrusion chains involving Vidar and the Supper backdoor, with some infections followed by Rhysida ransomware. Its use spans corporate environments rather than an established exclusive industry focus.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ANALYST NOTE: Interestingly, Oyster malware (which is likely related with the threat actor behind Lactrodectus) uses similar API endpoints for C2 communication.
The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers.
BlueVoyant assesses that Lorem Ipsum Loader is most likely a parallel or successor loader within Rapid Brigantine's toolkit rather than the same family Microsoft tracks as Oyster.
While the example campaign described in this section delivered Vidar Stealer, we have also observed this campaign distributing Lumma Stealer, Hijack Loader, and Oyster.
The lawsuit targets Fox Tempest’s infrastructure and also names Vanilla Tempest as a co-conspirator, a prominent ransomware group that used the service to deploy malware like Oyster, Lumma Stealer, and Vidar, and ransomware, including Rhysida, in multiple recent cyberattacks.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
It is primarily distributed via malvertising campaigns that deceive users into downloading trojanized installers for legitimate software, such as PuTTY, KeePass, WinSCP, Google Chrome, or Microsoft Teams.
In October 2025, MSTIC publicly attributed and disrupted a Rapid Brigantine campaign distributing fake MSTeamsSetup.exe files hosted on Teams-themed malicious domains ... driven by SEO poisoning and malvertising.
Analysis of the redirection chain determined that the attack likely originated from free movie streaming sites. Infections on such sites typically begin when users interact with embedded movie players or click popups.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
Opening the malicious attachment executes an HTML file with embedded JavaScript that is highly likely generated by an LLM. This script is designed to download and execute additional payloads
The ZIP file contains an LNK file that, when executed, runs a PowerShell script... likely generated using an LLM.
AI-Themed Brand Abuse A third category uses AI branding without meaningful AI integration. Filenames reference popular AI companies or other AI products, but the payload is conventional malware wrapped in an installer that mimics an AI application. The AI branding is a social engineering tactic, not a technical capability.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
In certain variants, the second-stage DLL drops an executable on disk. This executable is then launched, and the final third-stage DLL is injected into its memory.
Each function within DllMain contains embedded shellcode fragments. As functions execute in a predetermined order, these fragments are progressively copied into a allocated memory region.
the loader resolves essential Windows API functions—including LoadLibraryA, GetProcAddress, VirtualProtect, and InternetOpen—via dynamic resolution.
A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products... The single most widely encountered sample was an installer posing as a recipe-finding app called Recipe Lister... Oyster backdoor, posed as a Dropbox installer.
In certain variants, the second-stage DLL drops an executable on disk. This executable is then launched, and the final third-stage DLL is injected into its memory.
the North Koreans added three custom modules: browserlogin... companywallet... and cleanup (anti-forensic removal of workspace artifacts).
File Hash (SHA-256) 16474e9e4773fbc1e0b48a5025fad31b7f084b1beffb9a42687b4d01979885fe Dave-crypted IceNova
This second-stage payload is subsequently loaded using rundll32.exe (via exported function execution) and establishes persistence by creating a scheduled task that periodically re-executes the payload.
167 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
109 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor deployed in a Rhysida-related chain. It establishes persistence via the AlphaSecurity scheduled task and communicates with C2 domains before subsequent deployment of Vidar and Supper.
Backdoor delivered through a trojanized Dropbox-installer lure bearing a signature that purported to identify Dropbox as publisher. The article says AI tools are increasingly used to generate this type of delivery code for initial access.
Backdoor included in the research on AI-enabled malware. The summary does not detail its functionality, use of AI, or deployment activity.
Backdoor delivered via a fake Dropbox installer using an AutoIt loader and side-loading technique; presented as part of AI-assisted initial access and delivery activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.