Oyster backdoor

Backdoor

APT

Windows

Oyster backdoor

Oyster backdoor

Oyster (also known as Broomstick or CleanUpLoader) is a backdoor malware that was first seen in July 2023. Written in C++, it allows for remote sessions and can do file transfers and command line operations. Oyster has been used by various threat actors to support ransomware attacks.

Key Insights

Key Insights

Oyster infects systems through deceptive means such as malvertising. Users looking for popular software like Microsoft Teams or Google Chrome are directed to fake websites offering trojanized installers. When users download and run these installers, the Oyster backdoor is dropped and the attackers get access to the compromised systems.

Features

Once installed Oyster collects system info and talks to its command-and-control (C2) server. It can execute commands via cmd.exe and run additional files, giving the attacker full control of the infected host. This allows for the deployment of further malicious payloads including ransomware.

Evolution and Connections

First seen by IBM researchers in September 2023, Oyster has been associated with various cybercriminal activity. The Rhysida ransomware operation targeted an academic institution using the Oyster backdoor to deliver ransomware. This shows Oyster is being used to support more destructive malware.

Known Variants

Known Variants

Oyster is also known as Broomstick and CleanUpLoader in other reports. These are the same malware family with the same functionality and behavior.

Oyster is also known as Broomstick and CleanUpLoader in other reports. These are the same malware family with the same functionality and behavior.

Mitigation Strategies

Mitigation Strategies

  • Be careful when downloading software; check the source is legitimate.

  • Use web filtering to block known malicious sites.

  • Keep your security software up to date to detect and prevent malware.

  • Run security awareness training to educate users about phishing and malvertising.

Targeted Industries or Sectors

Targeted Industries or Sectors

Oyster has been seen in various sectors including academia and legal services. The malvertising campaigns for Oyster target users looking for popular software downloads so any industry can be affected.

Oyster has been seen in various sectors including academia and legal services. The malvertising campaigns for Oyster target users looking for popular software downloads so any industry can be affected.

Associated Threat Actors

Associated Threat Actors

Oyster is associated with the Russian linked threat group ITG23 also known as Periwinkle Tempest, Wizard Spider or Gold Blackburn. This group is known for distributing TrickBot malware and other cybercriminal activity.

Oyster is associated with the Russian linked threat group ITG23 also known as Periwinkle Tempest, Wizard Spider or Gold Blackburn. This group is known for distributing TrickBot malware and other cybercriminal activity.

References

    Related Posts:

    Rekoobe Backdoor Discovered in Open Directory, Possibly Targeting TradingView Users
    Oct 24, 2024

    Rekoobe Backdoor Discovered in Open Directory, Possibly Targeting TradingView Users

    Rekoobe Backdoor Discovered in Open Directory, Possibly Targeting TradingView Users
    Oct 24, 2024

    Rekoobe Backdoor Discovered in Open Directory, Possibly Targeting TradingView Users

    Rekoobe Backdoor Discovered in Open Directory, Possibly Targeting TradingView Users
    Oct 24, 2024

    Rekoobe Backdoor Discovered in Open Directory, Possibly Targeting TradingView Users

    ToneShell Backdoor Used to Target Attendees of the IISS Defence Summit
    Sep 3, 2024

    ToneShell Backdoor Used to Target Attendees of the IISS Defence Summit

    ToneShell Backdoor Used to Target Attendees of the IISS Defence Summit
    Sep 3, 2024

    ToneShell Backdoor Used to Target Attendees of the IISS Defence Summit

    ToneShell Backdoor Used to Target Attendees of the IISS Defence Summit
    Sep 3, 2024

    ToneShell Backdoor Used to Target Attendees of the IISS Defence Summit

    A Simple Approach to Discovering Oyster Backdoor Infrastructure | Hunt.io
    Jul 23, 2024

    A Simple Approach to Discovering Oyster Backdoor Infrastructure

    A Simple Approach to Discovering Oyster Backdoor Infrastructure | Hunt.io
    Jul 23, 2024

    A Simple Approach to Discovering Oyster Backdoor Infrastructure

    A Simple Approach to Discovering Oyster Backdoor Infrastructure | Hunt.io
    Jul 23, 2024

    A Simple Approach to Discovering Oyster Backdoor Infrastructure