Skip to main content
Mallory
Back to malware
MalwareUsed by 2 actors

OYSTERSHUCK

OYSTERSHUCK is a malware component used in a multi-stage intrusion chain attributed by CERT-UA to the Belarus-linked Ghostwriter threat group, also tracked as UAC-0057 and UNC1151, in phishing campaigns targeting Ukrainian government organizations since spring 2026. The infection chain uses phishing emails sent from compromised accounts with Prometheus-themed lures; attached PDFs contain links to ZIP archives holding a JavaScript file identified as OYSTERFRESH. OYSTERFRESH displays a decoy document, writes an obfuscated and encrypted payload named OYSTERBLUES to the Windows Registry, and downloads and launches OYSTERSHUCK. OYSTERSHUCK functions as a decoder for OYSTERBLUES, with reported decoding steps including string reversal, ROT13 transformation, and URL decoding. The broader malware chain collects host information from infected Windows systems, including computer name, username, operating system version, last boot time, and running processes, and sends it to attacker-controlled command-and-control infrastructure via HTTP POST; the infrastructure is reported to be commonly hidden behind Cloudflare and to frequently use .icu domains. Follow-on JavaScript may be executed via eval(), and CERT-UA assessed that later stages can deliver Cobalt Strike. Reported indicators associated with this campaign include the filename amplifier.js for OYSTERSHUCK, related components certificate.js (OYSTERFRESH), Oyster.js (OYSTERBLUES), EdgeSystemConfig.dll (CSBEACON), EdgeTaskMachine.js, the registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Blue'Oyster', Run keys MicrosoftEdgeUpdate and WindowsEdgeStartup, the scheduled task MicrosoftEdgeUpdateTaskMachine, and network indicators including hXXps://a3ufz.xsjdsb[.]icu/wp-json/prometheus-plus/certs-at-home/downloads and domains such as mickeymousegamesdealer.alexavegas[.]icu, productionsamplesoftheyear.cgdirector[.]icu, and advancedaisolutionsforeveryone.a1si[.]icu.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UNC1151

That JavaScript file, named OYSTERFRESH, handles two things simultaneously: it shows the victim a decoy document... and downloads a separate component called OYSTERSHUCK whose job is to decode and launch OYSTERBLUES when the time comes.

via security affairssecurityaffairs.com
Storm-0257

The malware chain ultimately deployed components known as OysterBlues and OysterShuck, which collect system information from infected devices and send it to attacker-controlled infrastructure hidden behind Cloudflare.

via the record mediatherecord.media
MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

2 techniques
T1566PhishingEvidence3

This activity, which began in the spring of 2026, involves sending phishing emails to government entities using compromised accounts.

T1566.001Spearphishing AttachmentEvidence1

Ghostwriter targeted Ukrainian government agencies with phishing emails delivering malware and Cobalt Strike payloads... phishing emails sent from already-compromised accounts — making the sender look legitimate — carrying PDF attachments.

Execution

1 technique
T1059.007JavaScriptEvidence1
TacticExecution

It then awaits further responses containing next-stage JavaScript code, which is executed using the eval() function.

Stealth

1 technique
T1027Obfuscated Files or InformationEvidence1
TacticStealth

...запис у реєстр операційної системи в обфускованому та закодованому вигляді програмного засобу OYSTERBLUES ... Для декодування послідовно виконуються, зокрема, реверсування рядка, перетворення ROT13 та URL-декодування.

Discovery

3 techniques
T1033System Owner/User DiscoveryEvidence1
TacticDiscovery

CERT-UA said the malware gathers details including the computer name, operating system version, user account information, and running processes.

T1057Process DiscoveryEvidence1
TacticDiscovery

CERT-UA said the malware gathers details including the computer name, operating system version, user account information, and running processes.

T1082System Information DiscoveryEvidence1
TacticDiscovery

The malware chain ultimately deployed components known as OysterBlues and OysterShuck, which collect system information from infected devices

T1071Application Layer ProtocolEvidence1

send it to attacker-controlled infrastructure hidden behind Cloudflare

T1105Ingress Tool TransferEvidence2

...as well as downloading and launching OYSTERSHUCK, which is responsible for decoding OYSTERBLUES.

INDICATORS OF COMPROMISE

IOCs tracked for this family

35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
6 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
18 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

Other
11 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app15 days ago
domain●●●●●●●●●●●●View more in app15 days ago
domain●●●●●●●●●●●●View more in app15 days ago
domain●●●●●●●●●●●●View more in app15 days ago
hash.md5●●●●●●●●●●●●View more in app15 days ago
hash.md5●●●●●●●●●●●●View more in app15 days ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching35

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution2

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.