HomeSecurityMalicious ads for PuTTY and Teams distribute malware

Malicious ads for PuTTY and Teams distribute malware

A malicious advertising campaign is exploiting legitimate software downloads to deploy the OysterLoader malware, previously identified as Broomstick and CleanUpLoader.

Malicious ads PuTTY Teams malware

This sophisticated initial access tool allows cybercriminals to establish a presence on corporate networks, ultimately acting as a distribution mechanism for the Rhysida ransomware.

Rhysida ransomware has targeted many businesses since it emerged from the Vice Society in 2021. It was renamed in 2023. Despite attempts to evade authorities through name changes, security researchers continue to monitor the hackers' evolving tactics.

See also: New TruffleNet BEC campaign leverages AWS SES

The current campaign, uncovered by Expel, represents the group’s second major malvertising . Since June 2025, the threat actors have significantly increased their attacks in intensity and scope.

Malicious ads for PuTTY and Teams distribute malware

Malicious ads mimic Teams, PuTTY, and Zoom to distribute malware

Recent campaigns have imitated popular software, such as Microsoft Teams, PuTTY, and Zoom, with threat actors creating nearly identical fake download pages.

Malicious PuTTY ads use this technique, with sponsored results intentionally misspelling the word "PuTTY" as "Putty", while still appearing legitimate enough to mislead users looking for the genuine remote access tool.

See also: New Phishing Attack Exploits Cloudflare and ZenDesk Pages

The effectiveness of OysterLoader comes from two main evasion techniques:

  • First, attackers package the malware through compression and obfuscation, hiding its true capabilities from security tools. This results in extremely low detection rates (with fewer than five antivirus engines typically flagging new samples).
  • Second, threat actors use code signing certificates, exploiting Windows trust mechanisms (to appear legitimate).
Malicious ads for PuTTY and Teams distribute malware

The scale of this operation is evident in the use of certificates. While a 2024 campaign used seven certificates, the current 2025 campaign has used over 40 unique code signing certificates, indicating a significant investment of resources and operational commitment.

See also: Hackers actively scan TCP ports 8530/8531 due to CVE-2025-59287 vulnerability in WSUS

Rhysida ransomware is not only based on OysterLoader. Expel researchers discovered that the gang is also developing the Latrodectus malware . In addition, Rhysida has exploited Microsoft's Trusted Signing Service, bypassing the 72-hour certificate validity restrictions

Microsoft says it has revoked over 200 certificates associated with this campaign, but businesses remain active. Security teams should remain vigilant against malicious advertising campaigns and verify software downloads only through official channels to avoid compromise.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS