Skip to content
Oyster Backdoor Malware Spread via Fake Downloads Targeting Financial Sector

Oyster Backdoor Malware Spread via Fake Downloads Targeting Financial Sector

First seen 15 Dec 2025, 16:48 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

Cybercriminals are distributing the Oyster backdoor malware disguised as popular office tools, including Microsoft Teams and Google Meet. This campaign, targeting individuals in the financial sector, has been active since at least mid-November 2025 and utilizes techniques such as SEO poisoning and malvertising to lure victims into downloading malicious software.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 183d ago How this analysis works

More articles in this cluster (1)

Following this threat?

Track Rhysida and Broomstick in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed