Attackers have launched a sophisticated malvertising and SEO poisoning campaign to distribute the Oyster backdoor by promoting fake Microsoft Teams installers. The campaign leverages search engine advertisements and manipulated search results for queries like "Teams download," redirecting unsuspecting users to a fraudulent website, teams-install[.]top, which closely mimics the legitimate Microsoft Teams download page. Upon visiting this site, users are prompted to download an installer named "MSTeamsSetup.exe," a filename identical to the official Microsoft Teams installer, increasing the likelihood of deception. The installer is code-signed with certificates from entities such as "4th State Oy" and "NRM NETWORK RISK MANAGEMENT INC," lending further legitimacy to the malicious file. When executed, the installer drops a malicious DLL, CaptureService.dll, into the %APPDATA%\Roaming directory and establishes persistence by creating a scheduled task named "CaptureService" that runs every 11 minutes. This ensures the Oyster backdoor remains active even after system reboots. Oyster, also known as CleanUpLoader and Broomstick, is a commodity backdoor first observed in mid-2023 and has been linked to multiple campaigns, including those supporting ransomware operations like Rhysida. The malware provides attackers with remote access, command execution capabilities, and the ability to deploy additional payloads or exfiltrate files. The campaign's use of SEO poisoning and malvertising mirrors previous tactics used to distribute Oyster via fake installers for other popular IT tools such as PuTTY and WinSCP. Security researchers from Blackpoint SOC identified and analyzed the campaign, highlighting the ongoing abuse of user trust in search results and well-known brands to facilitate initial access to corporate networks. The malicious activity underscores the persistent threat posed by commodity backdoors distributed through deceptive online advertising and the importance of verifying software sources. The campaign does not spoof Microsoft's actual domain but relies on visual mimicry and legitimate-seeming code signatures to bypass user suspicion. The deployment of the Oyster backdoor through this method enables attackers to establish a foothold in targeted environments, potentially leading to further compromise or ransomware deployment. Organizations are advised to educate users about the risks of downloading software from unofficial sources and to implement technical controls to block access to known malicious domains. The incident demonstrates the evolving tactics of threat actors in leveraging trusted brands and digital advertising infrastructure to propagate malware. Security teams should monitor for indicators of compromise related to Oyster and similar backdoors, particularly those delivered via malvertising. The campaign's discovery highlights the need for vigilance in both user behavior and technical defenses against social engineering and software supply chain threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A Sigma rule was published to help defenders detect Oyster malware activity associated with the fake Microsoft Teams installer campaign. The rule represents a new defensive artifact tied to the ongoing malvertising operation.
Blackpoint SOC disclosed that the fake Teams installer was code-signed with certificates tied to "4th State Oy" and "NRM NETWORK RISK MANAGEMENT INC," dropped a malicious CaptureService.dll into %APPDATA%\Roaming, and created a scheduled task for persistence every 11 minutes. The reporting highlighted IT administrators as likely targets and warned users to download software only from verified domains rather than search ads.
Threat actors began using SEO poisoning and search engine ads to lure users searching for "Teams download" to the fake domain teams-install[.]top. The site served a trojanized "MSTeamsSetup.exe" installer that delivered the Oyster backdoor on Windows systems.
Oyster, also known as Broomstick or CleanUpLoader, has been active since mid-2023 and is commonly distributed through malvertising campaigns impersonating popular IT tools. It has also been used as an initial access vector in later ransomware operations, including Rhysida intrusions.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcegithub.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.