logo

OysterLoader: Multi-Stage Loader Evolves to Evade Detection and Deliver Ransomware

ID: ce07f604-d087-591a-b858-76b0f79d1b66

STIX ID: report--ce07f604-d087-591a-b858-76b0f79d1b66

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Sekoia TDR analyzed OysterLoader (aka Broomstick/CleanUp), a C++ multi-stage malware loader distributed as fake installers that employs heavy API-call noise, anti-debugging, a custom LZMA compression variant, steganographic payload delivery inside images, and a dual-layer C2 using a non-standard Base64 with per-message random shifts; the report links it to cybercriminal operations including the Rhysida ransomware group and highlights active maintenance and evolving evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.