Friday, 28 November 2025
27.9 C
Singapore
14.5 C
Thailand
20.6 C
Indonesia
28.1 C
Philippines

Oyster malware campaign targets IT professionals with fake software tools

Oyster malware campaign targets IT professionals with fake tools like WinSCP and PuTTY, raising ransomware concerns.

A new malware campaign known as Oyster has been observed targeting IT professionals by disguising itself as popular software tools, including WinSCP and PuTTY. Researchers warn that the campaign could be linked to ransomware activity, raising concerns for enterprise security.

Malware hidden in trusted tools

Security firm BlueVoyant reported that its Security Operations Center (SOC) detected Oyster Backdoor within a healthcare client’s environment earlier this month. The attack was traced back to a malicious installer masquerading as WinSCP, a legitimate file transfer utility. Similar findings were made with installers posing as PuTTY, a commonly used administration tool.

Once installed, the malware enabled threat actors to create new administrator accounts and attempt lateral movement within the network. They also tried to deploy Havoc, a post-exploitation command and control framework, on a domain controller. BlueVoyant confirmed that its monitoring disrupted the attack before serious damage was done.

Evolving threat with advanced evasion

BlueVoyant researchers noted that the latest variant of Oyster shows several technical updates designed to avoid detection. The malware uses custom loaders that compress rather than encrypt payloads, relying on obfuscation techniques such as junk API calls and memory manipulation to complicate analysis.

The payload delivery component also performs anti-analysis checks, including sandbox detection and internet connectivity verification. If successful, it downloads and installs the Oyster Backdoor, setting up persistence through scheduled tasks. This enables the malware to maintain access and deploy additional malicious tools.

Connection to ransomware operators

According to BlueVoyant’s Threat Fusion Cell, Oyster is linked to activity attributed to the TAG-124 cluster and is believed to provide initial access for Rhysida ransomware. The Rhysida group has named at least ten victims on its leak site since June, underscoring the continued prevalence of ransomware attacks.

The campaign is also associated with SEO poisoning and typo-squatted domains designed to trick users into downloading trojanised software. Infrastructure linked to these operations has been found pushing malicious versions of widely used tools across IT environments.

Protecting against similar attacks

Experts recommend that IT teams only download software from trusted sources and avoid clicking on links or attachments in unsolicited emails. Organisations are advised to implement round-the-clock monitoring and subscribe to threat intelligence services to stay informed about the latest threats.

BlueVoyant highlighted that its global SOC, along with threat hunting and intelligence teams, continues to detect, investigate, and disrupt attacks like Oyster. The company stressed that campaigns of this nature remain active and represent a significant risk to enterprise systems.

Hot this week

OpenAI was blocked from using the term ‘cameo’ in Sora after a temporary court order

A judge blocks OpenAI from using the term “cameo” in Sora until 22 December as Cameo pursues its trademark dispute.

Asia’s boards place AI and digital transformation at the top of 2026 priorities

Nearly half of Asia’s governance leaders plan to prioritise AI in 2026 as digital transformation reshapes board agendas.

ChatGPT introduces new shopping research tool for personalised product guidance

ChatGPT launches a shopping research tool that creates personalised buyer’s guides through interactive product discovery.

Cybercriminals use fake Battlefield 6 downloads and trainers to spread malware

Malware disguised as pirated Battlefield 6 downloads and trainers is targeting players with stealers and C2 agents.

Battlefield 6 launches week-long free-to-play trial for new players

Battlefield 6 launches a week-long free trial with multiple playlists, map access, and progress carryover ahead of its Winter Offensive update.

ShadowV2 botnet spotted during AWS outage, researchers warn of possible return

ShadowV2 botnet briefly emerged during the AWS outage, targeting IoT devices, raising concerns about future cyberattacks.

Battlefield 6 launches week-long free-to-play trial for new players

Battlefield 6 launches a week-long free trial with multiple playlists, map access, and progress carryover ahead of its Winter Offensive update.

Sony announces December PS Plus Monthly Games lineup featuring five titles

Sony unveils a five-game PS Plus lineup for December, including Lego Horizon Adventures, Neon White, and several horror titles.

Global mobile gaming ads surge in 2025 as AI and interactivity reshape engagement

Mobile gaming ads grew strongly in 2025 as AI-driven optimisation and interactive formats reshaped global user acquisition strategies.

Related Articles

Popular Categories