Cybercriminals have launched a widespread campaign targeting users seeking to download Microsoft Teams by distributing fake installers embedded with the Oyster backdoor, also known as Broomstick. Attackers employ a combination of SEO poisoning and malvertising to ensure their malicious download pages appear prominently in search engine results and sponsored ads, increasing the likelihood that unsuspecting users will click on them. Victims who visit these spoofed websites, such as teams-install.top, are tricked into downloading a file named MSTeamsSetup.exe, which is designed to closely mimic the legitimate Teams installer. To further evade detection, the attackers have signed these fake installers with dubious digital certificates issued by companies like 4th State Oy and NRM NETWORK RISK MANAGEMENT INC., making the files appear trustworthy to both users and some security controls. Upon execution, the installer not only launches the real Microsoft Teams application to avoid arousing suspicion but also silently installs the Oyster backdoor in the background. This malware establishes command and control (C2) communications with attacker-controlled servers, such as nickbush24.com and techwisenetwork.com, enabling remote access and persistent control over the compromised system. The Oyster backdoor is highly versatile, allowing threat actors to gather system information, exfiltrate data, and potentially deploy additional payloads. Security researchers from Blackpoint Cyber have been actively monitoring this campaign and have highlighted the sophistication of the attackers' methods, including the use of legitimate-looking certificates and multi-stage delivery techniques. The campaign underscores the growing threat of supply chain and software impersonation attacks, particularly as users increasingly rely on web searches to obtain software. Organizations are advised to educate users about the risks of downloading software from unofficial sources, implement robust endpoint protection, and monitor for suspicious outbound connections indicative of C2 activity. The incident also highlights the importance of verifying digital signatures and scrutinizing the provenance of software installers, as attackers continue to refine their techniques to bypass traditional security measures. This campaign represents a significant escalation in the abuse of trusted brand names and software distribution channels to propagate advanced malware, posing risks to both individual users and enterprise environments. The use of malvertising and SEO manipulation demonstrates the attackers' adaptability and their focus on maximizing the reach and impact of their operations. Security teams should remain vigilant for similar tactics targeting other widely used collaboration and productivity tools.

Get the infrastructure and lures behind it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.