Skip to main content
Mallory
Back to malware
MalwareUsed by 2 actors

OYSTERFRESH

OYSTERFRESH is a JavaScript malware loader used in a phishing campaign attributed by CERT-UA to the Belarus-linked Ghostwriter threat actor, also tracked as UAC-0057 and UNC1151, targeting Ukrainian government organizations since spring 2026. Delivery observed in the reporting chain involved phishing emails sent from compromised accounts, themed around the legitimate Prometheus Ukrainian online learning platform, with PDF attachments containing links that downloaded a ZIP archive carrying the OYSTERFRESH JavaScript file. OYSTERFRESH displays a decoy document to distract the victim, writes an obfuscated and encoded payload named OYSTERBLUES into the Windows Registry, and downloads and launches the OYSTERSHUCK component, which decodes OYSTERBLUES. Reported decoding methods used by OYSTERSHUCK include string reversal, ROT13 transformation, and URL decoding. The follow-on OYSTERBLUES payload profiles the infected host by collecting the computer name, username, operating system version, last boot time, and running processes, then sends that information to command-and-control infrastructure via HTTP POST. It can receive additional JavaScript from the C2 and execute it via eval(), and CERT-UA assessed that the infection chain ultimately delivers Cobalt Strike. High-confidence host and network indicators mentioned in the reporting include file names certificate.js (OYSTERFRESH), amplifier.js (OYSTERSHUCK), Oyster.js (OYSTERBLUES), EdgeSystemConfig.dll (CSBEACON/Cobalt Strike Beacon), and EdgeTaskMachine.js; the registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Blue'Oyster'; Run keys MicrosoftEdgeUpdate and WindowsEdgeStartup; the scheduled task MicrosoftEdgeUpdateTaskMachine; the URL hXXps://a3ufz.xsjdsb[.]icu/wp-json/prometheus-plus/certs-at-home/downloads; and domains mickeymousegamesdealer.alexavegas[.]icu, productionsamplesoftheyear.cgdirector[.]icu, and advancedaisolutionsforeveryone.a1si[.]icu. CERT-UA also noted Ghostwriter infrastructure is commonly hidden behind Cloudflare and frequently uses .icu domains.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNC1151

The mentioned JS file is classified as OYSTERFRESH, which provides display of a decoy document, entry into the operating system registry in an obfuscated and encoded form of the OYSTERBLUES software tool, as well as loading and launching the OYSTERSHUCK component.

via security affairssecurityaffairs.com
Storm-0257

The phishing email contained a PDF attachment with a malicious link that downloaded a ZIP archive carrying malware identified as OysterFresh.

via the record mediatherecord.media
MITRE ATT&CK

Techniques & procedures

10 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

3 techniques
T1566PhishingEvidence3

This activity, which began in the spring of 2026, involves sending phishing emails to government entities using compromised accounts.

T1566.001Spearphishing AttachmentEvidence4

Ghostwriter targeted Ukrainian government agencies with phishing emails delivering malware and Cobalt Strike payloads... phishing emails sent from already-compromised accounts — making the sender look legitimate — carrying PDF attachments.

T1566.002Spearphishing LinkEvidence2

Inside the PDF is a link that, when clicked, downloads a ZIP archive containing a JavaScript file.

Execution

3 techniques
T1059.007JavaScriptEvidence2
TacticExecution

The mentioned JS file is classified as OYSTERFRESH... OYSTERBLUES... waits for instructions, which arrive as JavaScript code executed on the fly using the eval() function.

T1204User ExecutionEvidence1
TacticExecution

Typically, the email contains a PDF attachment with a link that, when clicked, leads to the download of a ZIP archive containing a JavaScript file.

T1204.002Malicious FileEvidence2
TacticExecution

Inside the PDF is a link that, when clicked, downloads a ZIP archive containing a JavaScript file.

Persistence

2 techniques
T1112Modify RegistryEvidence2

This file, dubbed OYSTERFRESH, displays a decoy document while stealthily writing an obfuscated payload, OYSTERBLUES, to the Windows Registry.

T1547.001Registry Run Keys / Startup FolderEvidence2

OYSTERFRESH... provides display of a decoy document, entry into the operating system registry in an obfuscated and encoded form of the OYSTERBLUES software tool.

T1547.001Registry Run Keys / Startup FolderEvidence2

OYSTERFRESH... provides display of a decoy document, entry into the operating system registry in an obfuscated and encoded form of the OYSTERBLUES software tool.

Stealth

1 technique
T1036MasqueradingEvidence1
TacticStealth

The JavaScript file, dubbed OYSTERFRESH, is designed to display a decoy document as a distraction mechanism...

T1112Modify RegistryEvidence2

This file, dubbed OYSTERFRESH, displays a decoy document while stealthily writing an obfuscated payload, OYSTERBLUES, to the Windows Registry.

T1105Ingress Tool TransferEvidence1

...as well as downloading and launching OYSTERSHUCK, which is responsible for decoding OYSTERBLUES.

INDICATORS OF COMPROMISE

IOCs tracked for this family

67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
14 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
42 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
11 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app15 days ago
domain●●●●●●●●●●●●View more in app15 days ago
domain●●●●●●●●●●●●View more in app15 days ago
domain●●●●●●●●●●●●View more in app15 days ago
domain●●●●●●●●●●●●View more in app15 days ago
domain●●●●●●●●●●●●View more in app15 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching67

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping10

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.