Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Oyster

184
Global rank
187 infographic chevron month
Month rank
181 infographic chevron week
Week rank
0
IOCs

Oyster (also seen in reporting as Broomstick or CleanUpLoader) is a Windows backdoor/loader actively used in multi-stage intrusion campaigns. Recent campaigns weaponize SEO-poisoning and malvertising to trick IT and dev users into downloading trojanized installers (PuTTY, WinSCP, Microsoft Teams, etc.), which then drop Oyster to establish a persistent foothold and load additional payloads (often leading to data theft or ransomware).

Backdoor
Type
Unknown
Origin
1 September, 2023
First seen
14 July, 2026
Last seen
Also known as
Broomstick
CleanUpLoader

How to analyze Oyster with ANY.RUN

Type
Unknown
Origin
1 September, 2023
First seen
14 July, 2026
Last seen

IOCs

IP addresses
23.52.181.141
150.171.27.11
8.8.8.8
23.52.181.212
150.171.28.11
142.251.20.132
104.18.23.222
172.211.123.248
52.123.243.86
48.209.138.189
150.171.109.193
2.16.241.212
142.251.110.100
150.171.109.194
216.239.32.223
48.209.133.15
Hashes
0cf098dfe5bbb46fc0132b3cf0c54b06b4d2c8390d847ee2a65d20f9b7480f4c
9b32c491d0bfebdca1455f73c3c6f71796d433a39818c06c353da588de650f81
2824cf97513dc3ecc261f378bfd595ae95a5997e9d1c63f5731a58b1f8cd54f9
64e01bc292ba2ea1699576fcc445367047520ee895e290ccee20c24c9336d8ef
f9d31b278e215eb0d0e9cd709edfa037e828f36214ab7906f612160fead4b2b4
2445cad863be47bb1c15b57a4960b7b0d01864e63cdfde6395f3b2689dc1444b
ff702ca753a7e3b75f9d9850cc9343e28e8d60f8005a2c955c8ac2105532b2c9
af889c1deb6f9248961c2f8ba4307a8206d7163616a5b7455d17cead00068317
728d8cbd71263680a4e41399db65b3f2b8175d50ca630afd30643ced9ffe831f
22bc37b47ce8a832f39701641dc358357676e9be187a93a4c5d4b016e29238ae
cc3e9077fcc9bd0dfc5dd3924c6c48b8345f32cee24fccc508c279f45b2abe61
14895bf43ce9b76c0ff4f9aef93dbe8bb6ca496894870cf0c007b189e0cef00e
7ccc7b17bfe01c3c7dd33eff8f80d0b57fc9b175815e766c9c1c1e893725e20f
6c69ce0fe6fab14f1990a320d704fee362c175c00eb6c9224aa6f41108918ca6
5f4229d18e5606330146ee13bdf726e10c1e06cbb15368c47f1ae68abe9ce4ba
ec78ddd4ccf32b5d76ec701a20167c3fbd146d79a505e4fb0421fc1e5cf4aa63
41ce6a7b18364efecced0419b42165d4f86c43643bbe1043014d4142cf86186a
57f81a5fcbd1fefd6ec3cdd525a85b707b4eead532c1b3092daafd88ee9268ec
89082fb05229826bc222f5d22c158235f025f0e6df67ff135a18bd899e13bb8f
e848603b7a73a88e3fe7bffa20e83397f5d1e93e77babb31473cc99e654a27b7
Domains
www.bing.com
activation-v2.sls.microsoft.com
settings-win.data.microsoft.com
go.microsoft.com
edge.microsoft.com
google.com
self.events.data.microsoft.com
config.edge.skype.com
edgeassetservice.azureedge.net
client.wns.windows.com
update.googleapis.com
copilot.microsoft.com
api.edgeoffer.microsoft.com
www.googleapis.com
crl.microsoft.com
clients2.googleusercontent.com
www.microsoft.com
URLs
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=71&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://edge.microsoft.com/linkdoctor/api/v1/getcorrections
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://copilot.microsoft.com/c/api/user/eligibility
https://edge.microsoft.com/autofillservice/core/page/7622086163743040060/3162667482957485866?cidalgoversion=2
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:l-hnnxtxnxeyzxzyirsgnpc1erspp0q0o0205lyo2pu&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d207%2526e%253d1
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=71&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://update.googleapis.com/service/update2/json?cup2key=14:svdnzikiclia69qyd5bsnwxy0hgw3qvgd0sir_vsccu&cup2hreq=1fae1b65f0754594f8ebd19313617aeec4acfac47d8d1388ce3c3e1fb537631b
https://www.bing.com/api/shopping/v1/user/shoppingsettings
https://edge.microsoft.com/abusiveadblocking/api/v1/blocklist
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=edge_hub_apps_manifest_gz&version=4.11.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=domains_config_gz&version=3.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://edge.microsoft.com/entityextractiontemplates/api/v1/assets/find-assets?name=arbitration_priority_list&version=24.*.*&channel=stable&key=d414dd4f9db345fa8003e32adc81b362
https://clients2.googleusercontent.com/crx/blobs/acproer2zc8cgsxh3w97ool_-pgkhlaiii3sel8eaynhrisqxgf7rau9v6yjvxw1e7syhw2j6vqleheqkxjzoaglbnja3q65adkdvikrv7wfmjgaqud8kltaav-hxvg30nwaxlka5qtua4oz5ic-cukgokgc_nvmf1of/ghbmnnjooekpmoecnnnilnnbdlolhkhi_1_107_1_0.crx
https://edgeassetservice.azureedge.net/assets/domains_config_gz/3.0.12/asset?assetgroup=entityextractiondomainsconfig
https://edgeassetservice.azureedge.net/assets/edge_hub_apps_manifest_gz/4.11.81/asset?assetgroup=shoreline
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2536
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7351
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10494
comments 0

Unveiling the Oyster Backdoor: A Stealthy Threat in the Shadows of Malvertising

Key Takeaways

  1. Oyster = loader/backdoor: Often observed as Oyster/Broomstick/CleanUpLoader and used as an initial access/loader stage.
  2. Primary lure: Trojanized installers + SEO poisoning. Attackers target IT pros by faking downloads for PuTTY, WinSCP, Teams, etc.
  3. Persistence pattern to hunt: Look for scheduled tasks executing rundll32 and unusual DLLs (e.g., twain_96.dll) and short-interval tasks.
  4. Network detection: Monitor for suspicious HTTPS callbacks to newly registered domains; combine with proxy/DNS logs to spot trojanized download pages.
  5. Prevention wins: Reduce risk by enforcing download policies, restricting admin rights, using app allowlists, and practicing good backup hygiene.
  6. Use a sandbox for rapid triage: Detonate suspicious installers to capture behavior (scheduled tasks, DLL execution, C2) before allowing enterprise deployment. (Run these in isolated sandboxes.) ANY.RUN’s Interactive Sandbox provides safe environment, smart anti-evasion techniques, and full visibility of the attack chain.

View Oyster backdoor in action:.

Oyster Backdoor sandbox analysis Oyster Backdoor in the Sandbox: processes, connections, files, IOCs, and more

  1. Leverage TI Lookup for rapid threat validation: When suspicious downloads, domains, or file hashes are encountered, TI Lookup provides instant threat intelligence validation. Security teams can quickly determine whether indicators are associated with Oyster campaigns, enabling immediate defensive actions. Integrating TI Lookup into security workflows accelerates incident detection and response, reducing attacker dwell time and limiting damage.

domainName:"partycybertrap.com""

Domain tagged by TI Lookup as Oyster backdoor infrastructure Domain tagged by TI Lookup as Oyster backdoor infrastructure

What is Oyster Backdoor Malware?

Oyster Backdoor represents a modular, multistage threat designed for stealth and versatility in cybercriminal operations. First identified by IBM researchers in September 2023 (though samples date back to July) it functions as a loader and backdoor, allowing attackers to establish command-and-control (C2) communications while blending into normal system activity.

Its common behaviors include: creating persistence (scheduled tasks), executing a malicious DLL via rundll32 (DLL registration/export abuse), communicating with command-and-control (C2) over HTTPS, using string obfuscation and process injection to evade detection, and acting as a staging loader for follow-on payloads (credential stealers, Cobalt-like tools, ransomware). Analysts have observed operators using Oyster to perform reconnaissance and hands-on-keyboard activity after initial deployment.

Unlike more rudimentary malware, Oyster's lightweight design supports a range of post-exploitation activities, from reconnaissance to payload delivery, making it a favorite among ransomware affiliates. Its evolution includes updated variants in 2024 and 2025, incorporating encrypted C2 protocols and reduced obfuscation for faster deployment. Linked to groups like ITG23 (also known as Wizard Spider or Periwinkle Tempest), Oyster has been commoditized as Malware-as-a-Service (MaaS), lowering the barrier for less sophisticated actors to launch targeted intrusions.

By masquerading as trusted applications like Microsoft Teams, Google Chrome, PuTTY, and WinSCP, Oyster exploits user trust to gain initial access to corporate environments, making it a significant threat to organizations across all sectors.

Oyster infiltrates via social engineering, exploiting malvertising and SEO poisoning on search engines like Google and Bing. Users searching for "Teams download" or "PuTTY installer" encounter sponsored ads or top results leading to spoofed sites. These host signed EXEs mimicking legitimate installers (e.g., MSTeamsSetup.exe), which drop the DLL post-execution while launching the real app to avoid suspicion.

Spread occurs laterally via RCE: attackers scan RDP ports, create admin accounts, and deploy to connected endpoints. No self-propagation like worms; reliance on human error and network traversal amplifies its reach in enterprise

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

Oyster Backdoor Victimology

Oyster primarily targets Windows users worldwide, with a focus on English-speaking regions such as the United States, United Kingdom, Germany, France, and Italy. Its campaigns disproportionately affect IT professionals and organizations in sectors vulnerable to ransomware, including healthcare, education, academia, legal services, and manufacturing. For instance, Rhysida ransomware operators known for hitting education (30% of victims) use Oyster to breach academic institutions.

Healthcare stands out due to targeted lures like fake PuTTY and WinSCP installers aimed at admins managing sensitive networks. Broader campaigns via fake Teams or Chrome downloads ensnare general users, but corporate endpoints provide the real value for lateral movement and extortion

How Oyster Backdoor Functions

Understanding Oyster's technical operation provides insights into detection and prevention strategies.

Initial Execution

The infection begins when a victim downloads and executes a trojanized installer from a malicious website. Upon execution, the installer extracts embedded resources, including malicious DLL files stored in the resource section of the executable.

Persistence Establishment

Oyster establishes persistence through scheduled tasks created with names like "CaptureService" or similar innocuous identifiers. Some variants use the DllRegisterServer export, while others leverage custom exports for execution. This ensures the malware remains active across system reboots and standard cleanup procedures.

Command and Control Communication

Once established, Oyster initiates communication with hard-coded C2 servers. The malware employs multiple C2 domains for redundancy, ensuring continued operation if one server is taken down. Communication protocols have evolved, with newer versions using substitution ciphers and custom encoding to obfuscate traffic and evade network monitoring.

System Reconnaissance

The malware performs comprehensive system profiling, collecting information about the operating system version, installed software and security products, user accounts and privileges, network configuration and domain membership, running processes and services, and available storage and file systems. This intelligence is transmitted to operators who use it to determine the value of the compromised system and plan subsequent attack stages.

Command Execution

The backdoor supports remote command execution, allowing operators to issue arbitrary commands through cmd.exe. This capability enables a wide range of malicious activities including file manipulation, credential harvesting, lateral movement preparation, security tool disablement, and additional payload deployment.

Payload Delivery

Oyster's modular architecture allows operators to download and execute additional tools based on attack objectives. Documented secondary payloads include Cobalt Strike beacons for hands-on-keyboard operations, PowerShell scripts (SILENTKILL) for defense evasion, credential theft tools, network scanning utilities, and ultimately, Rhysida ransomware binaries.

Oyster Backdoor Real-Time Analysis

By detonating an Oyster sample in ANY.RUN’s Interactive Sandbox one can observe it leverage invalid certificates, persistence mechanics and C2 communications.

View a sandbox analysis session of Oyster Backdoor.

Oyster Backdoor sandbox analysis Oyster Backdoor in the Sandbox: processes, connections, files, IOCs, and more

Attackers imitate legitimate software download pages to lure users into downloading a malicious app.

Fake Microsoft Teams page spreading Oyster Backdoor Fake Microsoft Teams page spreading Oyster Backdoor

The apps infected by Oyster usually have a compromised certificate, most often it’s expired, revoked or invalid due to modifications:

A certificate revoked by issuer A certificate revoked by issuer

After launching the application, a DLL library is created and executed, serving as the primary component of the backdoor. In this case, the file is disguised as WindowsCodecs.dll.

Malicious DLL library Malicious DLL library

Oyster's persistence is achieved through the Windows Task Scheduler. In our example, the task is configured to run every 18 minutes.

The malware sets up Windows Task Scheduler The malware sets up Windows Task Scheduler

Attention should be paid to the mutexes created by instances of this malicious software. They are hardcoded in the code, making them useful indicators of compromise.

Oyster Backdoor mutex An Oyster Backdoor mutex

Analysis reveals the backdoor's network activity, which is directed toward communication with C2 servers. This activity may vary depending on the state of the C2 server.

In this analysis, data is observed being downloaded with the MIME type application/x-x509-cert, indicating an attempt to exchange certificates or related data for authentication or further commands.

Oyster Backdoor downloads data Oyster Backdoor downloads data

Gathering Threat Intelligence on Oyster Backdoor Malware

Threat intelligence provides critical capabilities for detecting, preventing, and responding to Oyster backdoor threats. It helps enrich detection rules with specific indicators associated with Oyster.

SIEM systems incorporate IOCs to generate alerts when suspicious activity occurs. EDR platforms leverage threat intelligence to identify malicious processes and network connections. This intelligence-driven approach significantly improves detection accuracy and reduces false positives.

Threat intelligence feeds deliver timely information about emerging Oyster campaigns, including new C2 infrastructure, updated file hashes, malicious domains, and TTPs employed by attackers. Security teams can proactively block known malicious indicators before they impact the organization. Intelligence about typosquatted domains enables preemptive blocking or monitoring, preventing employee exposure to fake download sites.

Use ANY.RUN’s Threat Intelligence Lookup to search IOCs and behavior data linked to Oyster backdoor. Start from querying the threat name to find Oyster's samples that ANY.RUN’s community of 500K professionals and 15K SOC teams has already analyzed. Study TTPs and gather indicators:

threatName:"Oyster"

Oyster backdoor sample analyses found via TI Lookup Oyster backdoor sample analyses found via TI Lookup

Add an IOC to the search query to get a selection of indicators to use for monitoring, detection, and alerts:

threatName:"Oyster" and domainName:""

Oyster backdoor sample analyses found via TI Lookup Oyster backdoor sample analyses found via TI Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

Oyster Backdoor represents a significant and evolving threat, serving as a critical tool for cybercriminals’ ransomware operations and targeted intrusions. Its distribution through malvertising and SEO poisoning, combined with its modular architecture and evasion capabilities, makes it a formidable challenge for organizations of all sizes and sectors.

Effective defense against Oyster requires comprehensive security strategies spanning multiple domains. Technical controls including endpoint protection, network security, and access management form the foundation. However, human factors remain critical: user education about malvertising threats and software download risks significantly reduces exposure.

Timely intelligence about new campaigns, IOCs, and attacker TTPs enables proactive defense, early detection, and rapid response. Organizations leveraging both commercial and open-source intelligence, integrated into security tools and processes, significantly improve their defensive posture.

Start gathering actionable threat intelligence on Oyster backdoor by signing up to ANY.RUN’s TI Lookup: protect your business with timely detection and response.

HAVE A LOOK AT

DragonForce screenshot
DragonForce
dragonforce
DragonForce is a ransomware strain operating under the Ransomware-as-a-Service (RaaS) model. First reported in December 2023, it encrypts files with ChaCha8, renames them with random strings, and appends “.dragonforce_encrypted.” By disabling backups, wiping recovery, and spreading across SMB shares, DragonForce maximizes damage and pressures victims into multimillion-dollar ransom negotiations. It has targeted manufacturing, construction, IT, healthcare, and retail sectors worldwide, making it a severe threat to modern enterprises.
Read More
Balada Injector screenshot
Balada Injector is a long-running malware campaign that targets WordPress websites by exploiting vulnerabilities in plugins and themes. The attackers inject malicious code into compromised sites, leading to unauthorized redirects, data theft, and the creation of [backdoors](https://any.run/malware-trends/backdoor) for persistent access. The campaign operates in waves, with spikes in activity observed every few weeks, continually adapting to exploit newly discovered vulnerabilities.
Read More
GREENBLOOD screenshot
GREENBLOOD
greenblood
GREENBLOOD is a Go-based ransomware that uses concurrent ChaCha8 encryption to lock entire Windows environments in under a minute while systematically destroying backups, disabling defenses, and threatening double extortion through a Tor-based data leak site.
Read More
 screenshot
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
Gunra screenshot
Gunra
gunra
Gunra ransomware, a financially motivated threat actor that emerged in April 2025, deploys double-extortion tactics to encrypt victims' data and threaten leaks of exfiltrated information, primarily targeting Windows and Linux systems across healthcare, manufacturing, and other sectors worldwide.
Read More
RedLine screenshot
RedLine
redline stealer redline stealer malware
RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.
Read More