logo

OysterLoader Multi‑Stage Evasion Loader Uncovered with Advanced Obfuscation and Rhysida Ransomware Links

ID: 2c3005fb-0039-5d62-9a31-4503767c4cad

STIX ID: report--2c3005fb-0039-5d62-9a31-4503767c4cad

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-02-13

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

OysterLoader is a sophisticated multi-stage malware loader distributed via fake, digitally signed MSI installers that employs steganography, RC4-encrypted payloads hidden in icon files, timing- and API-based anti-analysis, and scheduled-task persistence to deliver ransomware (Rhysida) and infostealers (e.g., Vidar); analysts observed two-tier C2 infrastructure and evolving obfuscation techniques that complicate detection and network analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.