The provided article set does not mention an Oyster malware family.
Overview
The provided article set does not mention an Oyster malware family. Instead, it discusses Rhysida ransomware being deployed via fake Microsoft Teams advertisements, highlighting how threat actors abuse legitimate collaboration tools and ad ecosystems to deliver ransomware.
Related Threat Clusters
-
Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
33 articles · Updated May 19, 2026 -
Teenagers Plead Guilty to £39M Cyber Attack on Transport for London
Thalha Jubair, 20, and Owen Flowers, 18, have pleaded guilty to a cyber attack on Transport for London (TfL) that occurred between August 29 and September 6, 2024. The attack, attributed to the Scattered Spider hacking…
119 articles · Updated June 22, 2026 -
C2Looper Backdoor Exploits GitHub for Command-and-Control Operations
In July 2026, Zscaler ThreatLabz identified C2Looper, a Rust-based backdoor likely linked to ransomware actors. The malware employs a multi-stage ClickFix infection chain and utilizes GitHub repositories for…
3 articles · Updated August 18, 2026 -
Oyster Backdoor Malware Spread via Fake Downloads Targeting Financial Sector
Cybercriminals are distributing the Oyster backdoor malware disguised as popular office tools, including Microsoft Teams and Google Meet. This campaign, targeting individuals in the financial sector, has been active…
1 article · Updated December 15, 2025 -
Enhanced pkr_mtsi Malware Loader Distributes Multiple Payloads
The pkr_mtsi malware loader has been upgraded to incorporate advanced stealth techniques, including hashed API resolution and improved obfuscation. Initially observed in April 2025, it is utilized for deploying various…
2 articles · Updated January 8, 2026 -
Rhysida Ransomware Gang Uses Fake Microsoft Teams Ads for Malware Distribution
The Rhysida ransomware group is exploiting fake advertisements for Microsoft Teams to distribute malware, specifically targeting users searching for the software. This campaign employs malvertising techniques,…
8 articles · Updated November 4, 2025 -
Rhysida Ransomware Gang Uses Fake Microsoft Teams Ads to Infect Users
The Rhysida ransomware gang is exploiting fake ads for Microsoft Teams to distribute malware. Users searching for Microsoft Teams may encounter these deceptive links, which lead to data exfiltration or encryption…
3 articles · Updated November 2, 2025
Recent Intelligence Reports
- C2Looper Backdoor Uses GitHub for C2 | ThreatLabz - Zscaler, Inc. — Zscaler · August 17, 2026
- Two members of criminal hacking group plead guilty to £39m TfL hack — Independent · June 22, 2026
- Microsoft shuts down illegal code — Theregister · May 19, 2026
- Cybercrime service disrupted for abusing Microsoft platform to sign malware — Bleepingcomputer · May 19, 2026
- Microsoft disrupts cybercrime service that abused software verification systems en masse — Cyberscoop · May 19, 2026
- Microsoft Takes Down Fox Tempest for Providing Ransomware — Infosecurity-Magazine · May 19, 2026
- Increased stealth integrated into flexible pkr_mtsi malware loader — Scworld · January 8, 2026
- Versatile Malware Loader pkr_mtsi Delivers Diverse Payloads — Infosecurity-Magazine · January 7, 2026