OYSTERBLUES is an information-stealing malware component used in a multi-stage intrusion chain attributed by CERT-UA to the Belarus-aligned threat actor UNC1151, also known as Ghostwriter and UAC-0057. The campaign targeted Ukrainian government organizations beginning in spring 2026 and used spear-phishing emails sent from compromised accounts, themed around the legitimate Prometheus online learning platform. Victims were lured via PDF attachments containing links to ZIP archives that delivered a JavaScript component named OYSTERFRESH. OYSTERFRESH displayed a decoy document, stored an obfuscated or encoded OYSTERBLUES payload in the Windows Registry, and downloaded and launched OYSTERSHUCK, which decoded OYSTERBLUES using techniques including string reversal, ROT13 transformation, and URL decoding.
Once executed, OYSTERBLUES profiles the compromised Windows host by collecting the computer name, username, operating system version, last OS boot time, and a list of running processes. It exfiltrates this reconnaissance data to a command-and-control server via HTTP POST, then waits for follow-on JavaScript instructions from the server and executes them using the eval() function. Reporting states that the infection chain ultimately deployed or could deploy Cobalt Strike in later stages. CERT-UA also noted that the attacker infrastructure was commonly hidden behind Cloudflare and that many associated domains used the .icu top-level domain.
High-confidence host and network indicators mentioned in the reporting include the file name Oyster.js for OYSTERBLUES; related components certificate.js (OYSTERFRESH), amplifier.js (OYSTERSHUCK), and EdgeSystemConfig.dll (CSBEACON/Cobalt Strike Beacon); the registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Blue'Oyster'; persistence via Run keys 'MicrosoftEdgeUpdate' and 'WindowsEdgeStartup'; the scheduled task MicrosoftEdgeUpdateTaskMachine; and network indicators including hXXps://a3ufz.xsjdsb[.]icu/wp-json/prometheus-plus/certs-at-home/downloads, mickeymousegamesdealer.alexavegas[.]icu, productionsamplesoftheyear.cgdirector[.]icu, and advancedaisolutionsforeveryone.a1si[.]icu.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Late last month, the Computer Emergency Response Team of Ukraine (CERT-UA) attributed to the Belarus-aligned threat actor known as UNC1151 (aka Ghostwriter and UAC-0057) a spear-phishing campaign that targeted government organizations using compromised accounts to deliver an information stealer called OYSTERBLUES.
The malware chain ultimately deployed components known as OysterBlues and OysterShuck, which collect system information from infected devices and send it to attacker-controlled infrastructure hidden behind Cloudflare.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Late last month, the Computer Emergency Response Team of Ukraine (CERT-UA) attributed to the Belarus-aligned threat actor known as UNC1151 (aka Ghostwriter and UAC-0057) a spear-phishing campaign that targeted government organizations using compromised accounts to deliver an information stealer called OYSTERBLUES.
Late last month, the Computer Emergency Response Team of Ukraine (CERT-UA) attributed to the Belarus-aligned threat actor known as UNC1151 (aka Ghostwriter and UAC-0057) a spear-phishing campaign that targeted government organizations using compromised accounts to deliver an information stealer called OYSTERBLUES.
CERT-UA said the malware gathers details including the computer name, operating system version, user account information, and running processes.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information stealer delivered via spear-phishing campaigns using compromised accounts against government organizations.
Primary backdoor payload that performs host reconnaissance, exfiltrates system information to C2 over HTTP POST, and executes attacker-supplied JavaScript commands received from the server.
An intermediate payload that is stored in the Windows Registry, gathers host and process information, communicates with a command-and-control server, and downloads/launches OYSTERSHUCK.
An obfuscated and encrypted payload stored in the Windows Registry that collects host and process information, sends it to a C2 server, and executes next-stage JavaScript received from the server.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.