OYSTERSHUCK is a malware component used in a multi-stage intrusion chain attributed by CERT-UA to the Belarus-linked Ghostwriter threat group, also tracked as UAC-0057 and UNC1151, in phishing campaigns targeting Ukrainian government organizations since spring 2026. The infection chain uses phishing emails sent from compromised accounts with Prometheus-themed lures; attached PDFs contain links to ZIP archives holding a JavaScript file identified as OYSTERFRESH. OYSTERFRESH displays a decoy document, writes an obfuscated and encrypted payload named OYSTERBLUES to the Windows Registry, and downloads and launches OYSTERSHUCK. OYSTERSHUCK functions as a decoder for OYSTERBLUES, with reported decoding steps including string reversal, ROT13 transformation, and URL decoding. The broader malware chain collects host information from infected Windows systems, including computer name, username, operating system version, last boot time, and running processes, and sends it to attacker-controlled command-and-control infrastructure via HTTP POST; the infrastructure is reported to be commonly hidden behind Cloudflare and to frequently use .icu domains. Follow-on JavaScript may be executed via eval(), and CERT-UA assessed that later stages can deliver Cobalt Strike. Reported indicators associated with this campaign include the filename amplifier.js for OYSTERSHUCK, related components certificate.js (OYSTERFRESH), Oyster.js (OYSTERBLUES), EdgeSystemConfig.dll (CSBEACON), EdgeTaskMachine.js, the registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Blue'Oyster', Run keys MicrosoftEdgeUpdate and WindowsEdgeStartup, the scheduled task MicrosoftEdgeUpdateTaskMachine, and network indicators including hXXps://a3ufz.xsjdsb[.]icu/wp-json/prometheus-plus/certs-at-home/downloads and domains such as mickeymousegamesdealer.alexavegas[.]icu, productionsamplesoftheyear.cgdirector[.]icu, and advancedaisolutionsforeveryone.a1si[.]icu.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
That JavaScript file, named OYSTERFRESH, handles two things simultaneously: it shows the victim a decoy document... and downloads a separate component called OYSTERSHUCK whose job is to decode and launch OYSTERBLUES when the time comes.
The malware chain ultimately deployed components known as OysterBlues and OysterShuck, which collect system information from infected devices and send it to attacker-controlled infrastructure hidden behind Cloudflare.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
CERT-UA said the malware gathers details including the computer name, operating system version, user account information, and running processes.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Auxiliary component used to decode and launch the obfuscated OYSTERBLUES payload, acting as an intermediate execution stage in the infection chain.
A later-stage loader used to decode the final payload in the intrusion chain.
A secondary component downloaded and launched by OYSTERFRESH to decode the OYSTERBLUES payload.
JavaScript decoder/loader component used to decode OYSTERBLUES through string reversal, ROT13, and URL decoding, then facilitate its execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.