Oyster is a malware family tracked across 6 threat clusters and 9 intelligence report mentions on ThreatCluster. First observed November 2, 2025; most recent activity June 22, 2026.
The provided article set does not mention an Oyster malware family. Instead, it discusses Rhysida ransomware being deployed via fake Microsoft Teams advertisements, highlighting how threat actors abuse legitimate collaboration tools and ad ecosystems to deliver ransomware.
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
Thalha Jubair, 20, and Owen Flowers, 18, have pleaded guilty to a cyber attack on Transport for London (TfL) that occurred between August 29 and September 6, 2024. The attack, attributed to the Scattered Spider hacking…
Cybercriminals are distributing the Oyster backdoor malware disguised as popular office tools, including Microsoft Teams and Google Meet. This campaign, targeting individuals in the financial sector, has been active…
The pkr_mtsi malware loader has been upgraded to incorporate advanced stealth techniques, including hashed API resolution and improved obfuscation. Initially observed in April 2025, it is utilized for deploying various…
The Rhysida ransomware group is exploiting fake advertisements for Microsoft Teams to distribute malware, specifically targeting users searching for the software. This campaign employs malvertising techniques,…
The Rhysida ransomware gang is exploiting fake ads for Microsoft Teams to distribute malware. Users searching for Microsoft Teams may encounter these deceptive links, which lead to data exfiltration or encryption…