OysterLoader: Multi-Stage Loader Evolves to Evade Detection and Deliver Ransomware
ID: ce07f604-d087-591a-b858-76b0f79d1b66
STIX ID: report--ce07f604-d087-591a-b858-76b0f79d1b66
Feed Name: securityonline.info
Sekoia TDR analyzed OysterLoader (aka Broomstick/CleanUp), a C++ multi-stage malware loader distributed as fake installers that employs heavy API-call noise, anti-debugging, a custom LZMA compression variant, steganographic payload delivery inside images, and a dual-layer C2 using a non-standard Base64 with per-message random shifts; the report links it to cybercriminal operations including the Rhysida ransomware group and highlights active maintenance and evolving evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
