OysterLoader Unmasked: The Multi-Stage Evasion Loader
ID: d73edb1e-8249-5447-8e44-5afb6daba742
STIX ID: report--d73edb1e-8249-5447-8e44-5afb6daba742
Feed Name: Sekoia.io Blog
**OysterLoader (Broomstick/CleanUp)** is a sophisticated multi-stage C++ malware loader used since 2024 to deliver Rhysida ransomware and commodity payloads like Vidar; the report details its four-stage infection chain (TextShell packer, custom shellcode with LZMA decompression, downloader, and core DLL), extensive evasion (API flooding, dynamic API hashing, custom LZMA format, RC4+steganography), HTTP-based C2 with custom Base64 alphabets and hardcoded IPs/domains, persistence via scheduled tasks and signed MSI delivery, and provides IOCs and decoding scripts for detection and hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
