Oyster, also known as Broomstick and CleanUpLoader, is a Windows backdoor family first identified in 2023. Written in C++, it is commonly distributed through malvertising and SEO-poisoning campaigns that present trojanized installers for legitimate applications, including remote-access, productivity, browser, and meeting software. Campaigns have also used counterfeit installers with fraudulent or abused code-signing certificates.
Oyster establishes persistent remote access and supports command execution, reconnaissance, and delivery of follow-on payloads. It has been observed creating scheduled tasks that invoke DLL exports, enabling execution across reboots. The malware uses staged, reflective loading of DLL payloads and shellcode in memory, dynamically resolves Windows APIs, and incorporates anti-debugging behavior to reduce disk artifacts and impede analysis. Some variants use DLL sideloading with legitimate executables and may inject later-stage payloads into processes.
Oyster communicates with command-and-control infrastructure over HTTP or TLS and can register compromised hosts, obtain commands, and support operator hands-on-keyboard activity. It has been used as an initial foothold before deployment of information stealers, remote shells, credential-access tooling, and ransomware. Oyster activity has been associated with ransomware-related operations, including campaigns linked to Rhysida, and overlaps have been reported with the broader Rapid Brigantine ecosystem.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ANALYST NOTE: Interestingly, Oyster malware (which is likely related with the threat actor behind Lactrodectus) uses similar API endpoints for C2 communication.
The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers.
BlueVoyant assesses that Lorem Ipsum Loader is most likely a parallel or successor loader within Rapid Brigantine's toolkit rather than the same family Microsoft tracks as Oyster.
While the example campaign described in this section delivered Vidar Stealer, we have also observed this campaign distributing Lumma Stealer, Hijack Loader, and Oyster.
The lawsuit targets Fox Tempest’s infrastructure and also names Vanilla Tempest as a co-conspirator, a prominent ransomware group that used the service to deploy malware like Oyster, Lumma Stealer, and Vidar, and ransomware, including Rhysida, in multiple recent cyberattacks.
The service had been used to sign and distribute malware, including Rhysida ransomware, Oyster, Lumma Stealer, and Vidar, making malicious software appear legitimate and easier to deliver at scale.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
It is primarily distributed via malvertising campaigns that deceive users into downloading trojanized installers for legitimate software, such as PuTTY, KeePass, WinSCP, Google Chrome, or Microsoft Teams.
In October 2025, MSTIC publicly attributed and disrupted a Rapid Brigantine campaign distributing fake MSTeamsSetup.exe files hosted on Teams-themed malicious domains ... driven by SEO poisoning and malvertising.
Analysis of the redirection chain determined that the attack likely originated from free movie streaming sites. Infections on such sites typically begin when users interact with embedded movie players or click popups.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
Opening the malicious attachment executes an HTML file with embedded JavaScript that is highly likely generated by an LLM. This script is designed to download and execute additional payloads
The ZIP file contains an LNK file that, when executed, runs a PowerShell script... likely generated using an LLM.
AI-Themed Brand Abuse A third category uses AI branding without meaningful AI integration. Filenames reference popular AI companies or other AI products, but the payload is conventional malware wrapped in an installer that mimics an AI application. The AI branding is a social engineering tactic, not a technical capability.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
In certain variants, the second-stage DLL drops an executable on disk. This executable is then launched, and the final third-stage DLL is injected into its memory.
Each function within DllMain contains embedded shellcode fragments. As functions execute in a predetermined order, these fragments are progressively copied into a allocated memory region.
the loader resolves essential Windows API functions—including LoadLibraryA, GetProcAddress, VirtualProtect, and InternetOpen—via dynamic resolution.
A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products... The single most widely encountered sample was an installer posing as a recipe-finding app called Recipe Lister... Oyster backdoor, posed as a Dropbox installer.
In certain variants, the second-stage DLL drops an executable on disk. This executable is then launched, and the final third-stage DLL is injected into its memory.
the North Koreans added three custom modules: browserlogin... companywallet... and cleanup (anti-forensic removal of workspace artifacts).
File Hash (SHA-256) 16474e9e4773fbc1e0b48a5025fad31b7f084b1beffb9a42687b4d01979885fe Dave-crypted IceNova
This second-stage payload is subsequently loaded using rundll32.exe (via exported function execution) and establishes persistence by creating a scheduled task that periodically re-executes the payload.
149 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
105 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor delivered through a trojanized Dropbox-installer lure bearing a signature that purported to identify Dropbox as publisher. The article says AI tools are increasingly used to generate this type of delivery code for initial access.
Backdoor delivered via a fake Dropbox installer using an AutoIt loader and side-loading technique; presented as part of AI-assisted initial access and delivery activity.
Backdoor mentionné comme point de comparaison technique; ses endpoints API sont décrits comme similaires à ceux de C2Looper.
Mentioned only as a comparison point for similar C2 API endpoint usage.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.