OysterLoader Evolves With New C2 Infrastructure and Obfuscation
ID: 3bdba0e9-b945-5b66-9039-e56d42860634
STIX ID: report--3bdba0e9-b945-5b66-9039-e56d42860634
Feed Name: Infosecurity Magazine (News)
Threat Score
**OysterLoader** is an evolving, multi-stage C++ malware loader active from 2024–2026, linked to Rhysida ransomware and used to distribute commodity malware like Vidar; it employs a four-stage chain (TextShell packer, custom LZMA-decompressing shellcode, intermediate downloader, and a DLL core), dynamic API hashing, and an adaptive HTTP/HTTPS C2 with non-standard Base64 encoding and rotating endpoints to hinder detection and analysis.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
