HomeSecurityOysterLoader: The "silent" malware loader that worries experts

OysterLoader: The "silent" malware loader that worries experts

A highly sophisticated malware loader, known as OysterLoader, has emerged as one of the most serious threats in the modern cybersecurity landscape. It is a malware that leverages multiple layers of obfuscation and advanced anti-analysisto evade traditional detection systems and deliver dangerous payloads to infected devices.

OysterLoader

OysterLoader, written in C++, was first detected in June 2024 by Rapid7 and has been continuously evolving since then, becoming a key tool in high-risk attacks.

Distribution via fake websites and well-known apps

OysterLoader's main distribution method is based on deceptive campaigns using fake websitesthat mimic popular and legitimate applications. The perpetrators create copies of websites that look authentic and promote fake installers for programs such as PuTTy, WinSCP, Google Authenticator, and various artificial intelligence tools that are particularly popular with users.

See also: Lazarus campaign plants malicious npm and PyPI packages

In this way, the malware exploits users' trust in well-known brands, leading them to download infected files without realizing it.

Disguise as legitimate MSIs and digital signatures

One of the most alarming features of OysterLoader is that it disguises itself as Microsoft Installer (MSI) files. In many cases, these files even appear digitally signed, giving the illusion of legitimacy.

This makes the threat extremely insidious, as many users consider a digital signature to be a guarantee of security, which is no longer always the case.

The quadruple chain of infection

OysterLoader operates through a complex four-stage infection chain. The process begins with a packer called TextShell, continues with the execution of custom shellcode , and finally ends with the installation of the main malicious payload.

This multi-layered approach allows malware to evade analysis and significantly complicates efforts to detect it by endpoint security solutions.

See also: Phishing campaign combines old Office vulnerability with fileless XWorm RAT

OysterLoader: The "silent" malware loader that worries experts

Connection to Rhysida ransomware and the WIZARD SPIDER ecosystem

Researchers have linked OysterLoader primarily to campaigns by the Rhysida, a group considered particularly aggressive and dangerous. Rhysida is closely linked to WIZARD SPIDER, a cybercriminal network behind some of the most devastating attacks of the last decade.

At the same time, OysterLoader has been observed to distribute other commodity malware, such as Vidar, one of the most widespread info-stealers.

Two-tier command-and-control infrastructure

According to analysts at Sekoia, OysterLoader uses a two-tier command and control (C2) infrastructure. The initial servers handle the initial communication, while the final C2 servers handle the management of victims and sending additional commands.

This structure makes it more difficult to collapse the network, as neutralizing one server is not enough to completely stop the attack.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Anti-analysis techniques and continuous evolution

OysterLoader features advanced anti-analysis capabilities, such as API hammering, dynamic API resolution via custom hashing, and timing-based sandbox detection.

Its creators are constantly updating the code, modifying communication protocols and obfuscation techniques so that it remains effective against modern security solutions.

See also: AMOS infostealer targets macOS via popular AI app

Steganography and encryption within images

One of the most technically impressive elements is the use of steganography. After initial checks that require at least 60 active processes on the system, the malware communicates with C2 servers via HTTPS.

It then hides the next stage of infection within image files, disguising the code as simple visual content. The payload is protected with RC4 encryption and is detected by a marker pattern “endico”.

OysterLoader: The "silent" malware loader that worries experts

Persistence through scheduled tasks

Once decrypted, the payload is stored as a DLL in the AppData and executed via scheduled tasks every 13 minutes, ensuring a persistent presence on the system, even after reboots.

At the same time, communication is done with custom JSON encoding and non-standard Base64 alphabet, making network analysis.

A threat that requires increased vigilance

OysterLoader demonstrates how sophisticated modern malware loaders have become. Its connection to ransomware ecosystems, use of steganography, and anti-analysis techniques make it one of the most dangerous infection mechanisms of our time.

For organizations and users, being careful with downloads, using trusted sources, and strengthening cyber defenses is now more necessary than ever.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS