Oyster is a loader/backdoor malware family also known as Broomstick and CleanUpLoader. It has been linked to SEO-poisoning and malvertising campaigns that impersonate legitimate software installers and download pages, including Microsoft Teams, Google Meet, PuTTY, WinSCP, and KeePass. Reporting cited in the content states IBM publicly reported Oyster in September 2023.
Observed delivery involves trojanized installers presented on fake websites or malicious ads. In one reported infection chain, execution of the fake installer drops AlphaSecurity.dll and creates a scheduled task named "AlphaSecurity" that runs about every 18 minutes to maintain persistence across reboots. Related malicious DLL names mentioned in the content include CleanUp.dll and CleanUp30.dll.
The malware has been reported to collect victim information and exfiltrate it to hard-coded command-and-control infrastructure via HTTP POST, including use of the /api/connectivity path. Reported C2 indicators include supfoundrysettlers[.]us (64.95.10[.]243), wherehomebe[.]com (149.248.79[.]62), and retdirectyourman[.]eu (206.166.251[.]114). Additional suspected infrastructure identified through infrastructure pivoting includes codeforprofessionalusers[.]com (51.195.232[.]46), postmastersoriginals[.]com (139.99.221[.]140), firstcountryours[.]eu (162.19.237[.]181), and dotnetisforchildren[.]com (193.43.104[.]208).
The campaigns described in the content primarily targeted users in the financial sector, and broader activity was assessed as active from at least November 2024, with specific observed campaigns since mid-November 2025 and likely continuation through 2026. Some fake installers used filenames such as MSTeamsSetup.exe and were code-signed with certificates associated with LES LOGICIELS SYSTAMEX INC., Reach First Inc., and S.N. ADVANCED SEWERAGE SOLUTIONS LTD.; most of those abused certificates were later revoked. The content also notes reported ties between Oyster activity and human-operated ransomware groups, including Rhysida.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor delivered via SEO poisoning and malvertising using fake download pages (e.g., Microsoft Teams/Google Meet, previously PuTTY/WinSCP). When executed, it drops a malicious DLL (AlphaSecurity.dll) and establishes persistence via a scheduled task ('AlphaSecurity') that runs every 18 minutes, maintaining access across reboots.
Backdoor malware referred to as "Oyster Backdoor"; the content only indicates it is disguised as PuTTY and KeePass, without further behavioral details.
External Redirection Redirecting you to external site in 3 seconds : https://hunt.io/malware-families/oyster-backdoor
Backdoor distributed via malvertising and software impersonation (e.g., fake Microsoft Teams installer) that collects victim information and exfiltrates it to a hard-coded C2 domain over HTTP POST (noted /api/connectivity).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.