Oyster Backdoor Spreading via Trojanized Popular Software Downloads
ID: 167a1345-1bc3-5bec-9df1-1484e68580ca
STIX ID: report--167a1345-1bc3-5bec-9df1-1484e68580ca
Feed Name: The Hacker News
Rapid7 observed a malvertising campaign using trojanized installers of popular software (Google Chrome, Microsoft Teams) that deploy the Oyster backdoor (aka Broomstick/CleanUpLoader), which collects host information, communicates with hard-coded C2, and supports remote code execution; attackers then install legitimate Teams to avoid suspicion. The report also links activity to a Russia-associated group (ITG23/TrickBot), describes an email phishing campaign deploying NetSupport RAT, and details a phishing-as-a-service (ONNX Store) that uses QR-enabled PDFs, encrypted JavaScript, and a 2FA bypass to harvest credentials and relay authentication tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
