Scworld Oyster Backdoor Malware Spread via Fake Downloads Targeting Financial Sector
Article Content
Browse articles
Cybercriminals are distributing the Oyster backdoor malware disguised as popular office tools, including Microsoft Teams and Google Meet. This campaign, targeting individuals in the financial sector, has been active since at least mid-November 2025 and utilizes techniques such as SEO poisoning and malvertising to lure victims into downloading malicious software.
Ask AI about this cluster
Answers cite the sources they use
Updated 183d ago How this analysis works
More articles in this cluster (1)
Following this threat?
Track Rhysida and Broomstick in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique leverages node.exe, a legitimate and signed developer tool, allowing attackers to run interpreted scripts…
Ransomware Attack on Berlin Senate: Data Exfiltration and Phishing Vector In August 2026, the Berlin Senate Administration suffered a significant ransomware attack attributed to the group Rhysida, initiated by a phishing email that led to a fake CAPTCHA prompt. The attack exploited a method called TerminalFix, allowing attackers to execute malicious code and gain access to sensitive data.…