logo

Certified OysterLoader: Tracking Rhysida ransomware gang activity via code-signing certificates

ID: b772f088-02f7-5333-ab46-a91acd019e45

STIX ID: report--b772f088-02f7-5333-ab46-a91acd019e45

Feed Name: Expel Blog

Threat Score
78/100

Date Published: 2025-10-31

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

This report describes an ongoing malvertising campaign by the Rhysida ransomware gang that uses Bing search ads and fake download pages (impersonating Teams, PuTTY, Zoom) to distribute OysterLoader — an initial access tool — which enables deployment of persistent backdoors and ransomware; the actors evade detection using packing and numerous code-signing certificates (including abused Microsoft Trusted Signing), and the report includes extensive indicators (signer names and file hashes) and tracking data for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.