Rhysida ransomware operators have leveraged Microsoft's trusted signing system to deliver the OysterLoader malware, bypassing traditional security defenses. The attackers distributed the malware through malicious advertisements, including those targeting Microsoft Teams users, exploiting the trust associated with Microsoft's digital certificates to evade detection. This technique allowed the threat actors to deploy their payloads with a higher likelihood of success, as security solutions often treat signed binaries as legitimate.
The campaign involved the use of fake search ads to lure victims and facilitate the download of the malicious loader. By abusing the Microsoft trusted signing process, the attackers were able to slip their malware past endpoint protections, increasing the risk of successful ransomware deployment. Security researchers have highlighted the sophistication of this approach and the need for organizations to scrutinize even digitally signed files, as threat actors continue to find ways to exploit trusted mechanisms for malicious purposes.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that Rhysida or an associated supplier was using Microsoft's Trusted Signing service to sign malicious binaries, helping them appear legitimate and evade security controls. The campaign also used packing and obfuscation before signing to further reduce detection.
In a current campaign, the Rhysida ransomware operation used fake search advertisements on Microsoft Bing to redirect users to spoofed download pages for software such as Microsoft Teams, PuTTY, and Zoom. Victims who downloaded the files received the OysterLoader malware, which can establish persistence and fetch additional payloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecsoonline.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.