OysterLoader Unmasked: The Multi-Stage Evasion Loader
ID: 009c4d84-1e11-505c-a5f7-eac66597dabb
STIX ID: report--009c4d84-1e11-505c-a5f7-eac66597dabb
Feed Name: Sekoia.com
**OysterLoader (aka Broomstick / CleanUp)** is a sophisticated multi-stage Windows loader used since 2024 to deliver Rhysida ransomware and commodity malware like Vidar; the report details a four-stage chain (TextShell packer, custom shellcode with LZMA decompression, downloader, and final DLL core), numerous anti-analysis/obfuscation techniques, a custom Base64-like C2 encoding scheme and evolving C2 endpoints, persistence via scheduled tasks and APPDATA DLLs, and provides IOCs (C2 IPs/domains, RC4 key, filenames and task names).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
