Oyster, also known as Broomstick and CleanUpLoader, is a Windows C++ backdoor family first identified in 2023. It is commonly distributed through malvertising and SEO-poisoned download pages that offer trojanized installers for legitimate business and IT software, including collaboration and remote-administration products. Campaigns have used fraudulent or abused code-signing certificates to make these installers appear trustworthy.
Oyster establishes persistent remote access through scheduled tasks and can execute commands through the Windows command shell, conduct host and Active Directory reconnaissance, and retrieve or deploy follow-on payloads. It uses multi-stage, shellcode-based reflective DLL loading to map components into memory, reducing disk artifacts. Observed variants incorporate anti-debugging behavior, dynamic API resolution, and HTTP or TLS command-and-control communications. Some delivery and update flows abuse DLL sideloading with legitimate executables.
Oyster has been observed in intrusion chains involving Vidar and Supper, with subsequent hands-on-keyboard activity and ransomware deployment. It is associated with Rhysida-related activity tracked by Microsoft as Vanilla Tempest, and has been used against corporate networks across multiple sectors.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
ANALYST NOTE: Interestingly, Oyster malware (which is likely related with the threat actor behind Lactrodectus) uses similar API endpoints for C2 communication.
The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers.
BlueVoyant assesses that Lorem Ipsum Loader is most likely a parallel or successor loader within Rapid Brigantine's toolkit rather than the same family Microsoft tracks as Oyster.
While the example campaign described in this section delivered Vidar Stealer, we have also observed this campaign distributing Lumma Stealer, Hijack Loader, and Oyster.
The lawsuit targets Fox Tempest’s infrastructure and also names Vanilla Tempest as a co-conspirator, a prominent ransomware group that used the service to deploy malware like Oyster, Lumma Stealer, and Vidar, and ransomware, including Rhysida, in multiple recent cyberattacks.
The service had been used to sign and distribute malware, including Rhysida ransomware, Oyster, Lumma Stealer, and Vidar, making malicious software appear legitimate and easier to deliver at scale.
32 distinct techniques documented for this family, organized by ATT&CK tactic.
It is primarily distributed via malvertising campaigns that deceive users into downloading trojanized installers for legitimate software, such as PuTTY, KeePass, WinSCP, Google Chrome, or Microsoft Teams.
In October 2025, MSTIC publicly attributed and disrupted a Rapid Brigantine campaign distributing fake MSTeamsSetup.exe files hosted on Teams-themed malicious domains ... driven by SEO poisoning and malvertising.
Analysis of the redirection chain determined that the attack likely originated from free movie streaming sites. Infections on such sites typically begin when users interact with embedded movie players or click popups.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
Opening the malicious attachment executes an HTML file with embedded JavaScript that is highly likely generated by an LLM. This script is designed to download and execute additional payloads
The ZIP file contains an LNK file that, when executed, runs a PowerShell script... likely generated using an LLM.
AI-Themed Brand Abuse A third category uses AI branding without meaningful AI integration. Filenames reference popular AI companies or other AI products, but the payload is conventional malware wrapped in an installer that mimics an AI application. The AI branding is a social engineering tactic, not a technical capability.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
For persistence, the second-stage DLL creates a scheduled task that periodically executes the second-stage payload.
In certain variants, the second-stage DLL drops an executable on disk. This executable is then launched, and the final third-stage DLL is injected into its memory.
Each function within DllMain contains embedded shellcode fragments. As functions execute in a predetermined order, these fragments are progressively copied into a allocated memory region.
the loader resolves essential Windows API functions—including LoadLibraryA, GetProcAddress, VirtualProtect, and InternetOpen—via dynamic resolution.
A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products... The single most widely encountered sample was an installer posing as a recipe-finding app called Recipe Lister... Oyster backdoor, posed as a Dropbox installer.
In certain variants, the second-stage DLL drops an executable on disk. This executable is then launched, and the final third-stage DLL is injected into its memory.
the North Koreans added three custom modules: browserlogin... companywallet... and cleanup (anti-forensic removal of workspace artifacts).
File Hash (SHA-256) 16474e9e4773fbc1e0b48a5025fad31b7f084b1beffb9a42687b4d01979885fe Dave-crypted IceNova
This second-stage payload is subsequently loaded using rundll32.exe (via exported function execution) and establishes persistence by creating a scheduled task that periodically re-executes the payload.
151 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
106 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor deployed in a Rhysida-related chain. It establishes persistence via the AlphaSecurity scheduled task and communicates with C2 domains before subsequent deployment of Vidar and Supper.
Backdoor delivered through a trojanized Dropbox-installer lure bearing a signature that purported to identify Dropbox as publisher. The article says AI tools are increasingly used to generate this type of delivery code for initial access.
Backdoor delivered via a fake Dropbox installer using an AutoIt loader and side-loading technique; presented as part of AI-assisted initial access and delivery activity.
Backdoor mentionné comme point de comparaison technique; ses endpoints API sont décrits comme similaires à ceux de C2Looper.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.