logo

Fake Microsoft Teams installers push Oyster malware via malvertising

ID: 82eb6788-1f7b-5945-a4c2-6da936a0ba5b

STIX ID: report--82eb6788-1f7b-5945-a4c2-6da936a0ba5b

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-09-27

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

**Malicious SEO ads and a fake Microsoft Teams download site are delivering the Oyster backdoor (aka Broomstick/CleanUpLoader) to Windows devices; the trojanized MSTeamsSetup.exe is code-signed, drops CaptureService.dll into %APPDATA%\Roaming, and creates a scheduled task named "CaptureService" to achieve persistence — the backdoor has been observed in multiple campaigns and linked to ransomware operations such as Rhysida.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.