Oyster, also known as Broomstick and CleanUpLoader, is a Windows malware family observed since 2023 that functions as a modular backdoor and loader used to establish persistent remote access and deliver additional payloads. It has been associated with financially motivated intrusion activity and has been repeatedly linked to ransomware operations, particularly Rhysida, as well as campaigns involving other commodity malware such as Vidar and Lumma Stealer. Reporting also links Oyster-related activity to threat clusters including Vanilla Tempest and broader ecosystems supported by malware-signing services such as Fox Tempest.
Oyster is commonly distributed through malvertising and SEO-poisoning campaigns that impersonate legitimate software and collaboration tools, especially Microsoft Teams, Google Meet, Google Chrome, PuTTY, and WinSCP. Victims are lured to convincing download pages and execute trojanized installers, sometimes signed with fraudulently obtained certificates to reduce user suspicion and improve defense evasion. Recent campaigns also show Oyster delivered through fake software installers and, in some cases, directly deployed rather than via a separate dedicated loader.
Once executed, Oyster establishes persistence on compromised Windows systems, including through scheduled tasks, and launches malicious DLL components to maintain access across reboots. Observed behavior includes command-and-control communications, host information collection, remote access functionality, and delivery of follow-on malware. In intrusion chains, Oyster has served as an initial foothold that enabled subsequent deployment of infostealers, SOCKS-based backdoors, hands-on-keyboard reconnaissance, and ultimately ransomware. Victimology includes corporate environments and sectors such as travel and tourism, with broader downstream impact tied to healthcare, education, government, and other organizations targeted by affiliated ransomware actors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BlueVoyant assesses that Lorem Ipsum Loader is most likely a parallel or successor loader within Rapid Brigantine's toolkit rather than the same family Microsoft tracks as Oyster.
While the example campaign described in this section delivered Vidar Stealer, we have also observed this campaign distributing Lumma Stealer, Hijack Loader, and Oyster.
The lawsuit targets Fox Tempest’s infrastructure and also names Vanilla Tempest as a co-conspirator, a prominent ransomware group that used the service to deploy malware like Oyster, Lumma Stealer, and Vidar, and ransomware, including Rhysida, in multiple recent cyberattacks.
The service had been used to sign and distribute malware, including Rhysida ransomware, Oyster, Lumma Stealer, and Vidar, making malicious software appear legitimate and easier to deliver at scale.
The service had been used to sign and distribute malware, including Rhysida ransomware, Oyster, Lumma Stealer, and Vidar, making malicious software appear legitimate and easier to deliver at scale.
The service had been used to sign and distribute malware, including Rhysida ransomware, Oyster, Lumma Stealer, and Vidar, making malicious software appear legitimate and easier to deliver at scale.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
In July 2025, CyberProof Researchers reported on Oyster commonly spreading through malvertising campaigns that impersonate popular IT tools, such as Putty and WinSCP.
In October 2025, MSTIC publicly attributed and disrupted a Rapid Brigantine campaign distributing fake MSTeamsSetup.exe files hosted on Teams-themed malicious domains ... driven by SEO poisoning and malvertising.
Further analysis revealed that Fox Tempest expanded its offerings earlier this year by providing customers with pre-configured virtual machines hosted through Cloudzy infrastructure. Users could upload malware to these systems and receive digitally signed binaries generated through certificates controlled by the group.
For persistence, the installer creates a scheduled task named “AlphaSecurity” to execute the DLL every 18 minutes, ensuring the backdoor remains active even on reboots.
threat actors are promoting a fake site that appears when visitors search for “Microsoft Teams download”... serving Oyster backdoor with file name Google meet.
the North Koreans added three custom modules: browserlogin... companywallet... and cleanup (anti-forensic removal of workspace artifacts).
132 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
93 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an example of a RAT/backdoor used for long-term control in SEO-poisoning attack objectives.
A payload associated with Rhysida delivery infrastructure, referenced via a payload delivery domain and a Donut-packed sample.
A malware family/backdoor associated with Rapid Brigantine campaigns, delivered in fake Teams installer operations as a stepping stone to ransomware deployment.
Malware family observed as an additional payload distributed in the same AI-themed malvertising ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.