logo

Oyster Backdoor Spreading via Trojanized Popular Software Downloads

ID: 167a1345-1bc3-5bec-9df1-1484e68580ca

STIX ID: report--167a1345-1bc3-5bec-9df1-1484e68580ca

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-06-21

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Rapid7 observed a malvertising campaign using trojanized installers of popular software (Google Chrome, Microsoft Teams) that deploy the Oyster backdoor (aka Broomstick/CleanUpLoader), which collects host information, communicates with hard-coded C2, and supports remote code execution; attackers then install legitimate Teams to avoid suspicion. The report also links activity to a Russia-associated group (ITG23/TrickBot), describes an email phishing campaign deploying NetSupport RAT, and details a phishing-as-a-service (ONNX Store) that uses QR-enabled PDFs, encrypted JavaScript, and a 2FA bypass to harvest credentials and relay authentication tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.