OysterLoader Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
October 31, 2025
Last Seen
March 3, 2026

Related Threat Clusters

  • OysterLoader Malware Loader Revealed with Rhysida Ransomware Connections

    OysterLoader, a multi-stage malware loader, has been identified as a significant cybersecurity threat. First discovered in June 2024, this C++ malware employs advanced obfuscation techniques to avoid detection and is…

    5 articles · Updated February 13, 2026
  • Gootloader Malware Resurfaces, Compromises Domain Controllers

    Gootloader malware, known for delivering ransomware, has re-emerged after reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard…

    2 articles · Updated November 7, 2025
  • Gootloader Malware Resurfaces, Compromises Domain Controllers

    Gootloader malware has re-emerged after a period of reduced activity, with Huntress reporting three infections since October 27, 2025. Two of these incidents resulted in hands-on-keyboard intrusions, leading to domain…

    4 articles · Updated November 7, 2025
  • Shift in Ransomware Tactics Targeting Cloud Assets

    Ransomware actors are increasingly focusing on cloud-based assets, particularly in AWS environments. This shift involves utilizing various tactics to compromise critical business data, moving away from traditional…

    56 articles · Updated November 19, 2025
  • HP Reports Rise in Modular Malware Using AI Techniques

    HP's Threat Insights Report reveals that attackers are increasingly utilizing AI to create low-quality, modular malware campaigns. These campaigns leverage techniques such as 'vibe-hacking' and include infection scripts…

    8 articles · Updated March 3, 2026
  • Malicious Ads in PuTTY and Teams Deliver OysterLoader Malware

    Recent reports indicate that weaponized advertisements in PuTTY and Microsoft Teams are distributing OysterLoader malware, which grants attackers full access to devices and networks. This malware poses significant risks…

    2 articles · Updated November 4, 2025
  • Rhysida Ransomware Gang Uses Fake Microsoft Teams Ads for Malware Distribution

    The Rhysida ransomware group is exploiting fake advertisements for Microsoft Teams to distribute malware, specifically targeting users searching for the software. This campaign employs malvertising techniques,…

    8 articles · Updated November 4, 2025
  • Rhysida Ransomware Gang Uses Fake Microsoft Teams Ads to Infect Users

    The Rhysida ransomware gang is exploiting fake ads for Microsoft Teams to distribute malware. Users searching for Microsoft Teams may encounter these deceptive links, which lead to data exfiltration or encryption…

    3 articles · Updated November 2, 2025

Recent Intelligence Reports

  • Hackers use booking.com and Microsoft Teams in vibe coding campaigns ​ — Cybernews · March 3, 2026
  • OysterLoader Multi‑Stage Evasion Loader Uncovered with Advanced Obfuscation and Rhysida Ransomware Links — Cybersecuritynews · February 13, 2026
  • Gootloader malware back for the attack, serves up ransomware — Theregister · November 7, 2025
  • Gootloader malware back for the attack, serves up ransomware — Theregister · November 6, 2025
  • Rhysida gang now malvertising to people on Teams, Zoom, and PutTy — Cybernews · November 4, 2025
  • Ransomware-Bande missbraucht Microsoft — Csoonline · November 4, 2025
  • Malicious PuTTY Ads Deliver OysterLoader, Allowing Attackers Full Device and Network Access — Gbhackers · November 4, 2025
  • Rhysida ransomware exploits Microsoft certificate to slip malware past defenses — Csoonline · November 3, 2025

CVSS v3.1 Breakdown