Skip to content
OysterLoader Malware Loader Revealed with Rhysida Ransomware Connections

OysterLoader Malware Loader Revealed with Rhysida Ransomware Connections

First seen 13 Feb 2026, 10:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

OysterLoader, a multi-stage malware loader, has been identified as a significant cybersecurity threat. First discovered in June 2024, this C++ malware employs advanced obfuscation techniques to avoid detection and is primarily distributed via counterfeit websites mimicking legitimate software applications. It has been linked to the Rhysida ransomware, further complicating the threat landscape.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 202d ago How this analysis works

Timeline

2024-06-01
OysterLoader first identified by Rapid7
2026-02-13
OysterLoader's advanced obfuscation tactics reported

More articles in this cluster (5)

Following this threat?

Track Rhysida and OysterLoader in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed