logo

OysterLoader Evolves With New C2 Infrastructure and Obfuscation

ID: 3bdba0e9-b945-5b66-9039-e56d42860634

STIX ID: report--3bdba0e9-b945-5b66-9039-e56d42860634

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-02-16

Date Updated: 2026-04-22

...
...

**OysterLoader** is an evolving, multi-stage C++ malware loader active from 2024–2026, linked to Rhysida ransomware and used to distribute commodity malware like Vidar; it employs a four-stage chain (TextShell packer, custom LZMA-decompressing shellcode, intermediate downloader, and a DLL core), dynamic API hashing, and an adaptive HTTP/HTTPS C2 with non-standard Base64 encoding and rotating endpoints to hinder detection and analysis.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.