logo

OysterLoader Unmasked: The Multi-Stage Evasion Loader

ID: d73edb1e-8249-5447-8e44-5afb6daba742

STIX ID: report--d73edb1e-8249-5447-8e44-5afb6daba742

Feed Name: Sekoia.io Blog

Threat Score
78/100

Date Published: 2026-02-12

Date Updated: 2026-04-29

Author: Pierre Le Bourhis

...
...

**OysterLoader (Broomstick/CleanUp)** is a sophisticated multi-stage C++ malware loader used since 2024 to deliver Rhysida ransomware and commodity payloads like Vidar; the report details its four-stage infection chain (TextShell packer, custom shellcode with LZMA decompression, downloader, and core DLL), extensive evasion (API flooding, dynamic API hashing, custom LZMA format, RC4+steganography), HTTP-based C2 with custom Base64 alphabets and hardcoded IPs/domains, persistence via scheduled tasks and signed MSI delivery, and provides IOCs and decoding scripts for detection and hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.