Oysterâs Trail: Resurgence of Infrastructure Linked to Ransomware and Cybercrime Actors
ID: 11944219-abc6-5b1e-811b-2998fc6ced7d
STIX ID: report--11944219-abc6-5b1e-811b-2998fc6ced7d
Feed Name: Hunt.io Blog
Threat Score
This report documents the resurgence of the Oyster backdoor (also known as Broomstick/CleanUpLoader), detailing newly observed infrastructure—three primary IPs, multiple domains, a Let's Encrypt TLS certificate fingerprint, and shared SSH key associations—and linking activity to threat groups and malvertising campaigns; it provides IOCs and detection pivots for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
