A highly sophisticated malware loader, known as OysterLoader, has emerged as one of the most serious threats in the modern cybersecurity landscape. It is a malware that leverages multiple layers of obfuscation and advanced anti-analysisto evade traditional detection systems and deliver dangerous payloads to infected devices.

OysterLoader, written in C++, was first detected in June 2024 by Rapid7 and has been continuously evolving since then, becoming a key tool in high-risk attacks.
Distribution via fake websites and well-known apps
OysterLoader's main distribution method is based on deceptive campaigns using fake websitesthat mimic popular and legitimate applications. The perpetrators create copies of websites that look authentic and promote fake installers for programs such as PuTTy, WinSCP, Google Authenticator, and various artificial intelligence tools that are particularly popular with users.
See also: Lazarus campaign plants malicious npm and PyPI packages
In this way, the malware exploits users' trust in well-known brands, leading them to download infected files without realizing it.
Disguise as legitimate MSIs and digital signatures
One of the most alarming features of OysterLoader is that it disguises itself as Microsoft Installer (MSI) files. In many cases, these files even appear digitally signed, giving the illusion of legitimacy.
This makes the threat extremely insidious, as many users consider a digital signature to be a guarantee of security, which is no longer always the case.
The quadruple chain of infection
OysterLoader operates through a complex four-stage infection chain. The process begins with a packer called TextShell, continues with the execution of custom shellcode , and finally ends with the installation of the main malicious payload.
This multi-layered approach allows malware to evade analysis and significantly complicates efforts to detect it by endpoint security solutions.
See also: Phishing campaign combines old Office vulnerability with fileless XWorm RAT

Connection to Rhysida ransomware and the WIZARD SPIDER ecosystem
Researchers have linked OysterLoader primarily to campaigns by the Rhysida, a group considered particularly aggressive and dangerous. Rhysida is closely linked to WIZARD SPIDER, a cybercriminal network behind some of the most devastating attacks of the last decade.
At the same time, OysterLoader has been observed to distribute other commodity malware, such as Vidar, one of the most widespread info-stealers.
Two-tier command-and-control infrastructure
According to analysts at Sekoia, OysterLoader uses a two-tier command and control (C2) infrastructure. The initial servers handle the initial communication, while the final C2 servers handle the management of victims and sending additional commands.
This structure makes it more difficult to collapse the network, as neutralizing one server is not enough to completely stop the attack.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Anti-analysis techniques and continuous evolution
OysterLoader features advanced anti-analysis capabilities, such as API hammering, dynamic API resolution via custom hashing, and timing-based sandbox detection.
Its creators are constantly updating the code, modifying communication protocols and obfuscation techniques so that it remains effective against modern security solutions.
See also: AMOS infostealer targets macOS via popular AI app
Steganography and encryption within images
One of the most technically impressive elements is the use of steganography. After initial checks that require at least 60 active processes on the system, the malware communicates with C2 servers via HTTPS.
It then hides the next stage of infection within image files, disguising the code as simple visual content. The payload is protected with RC4 encryption and is detected by a marker pattern “endico”.

Persistence through scheduled tasks
Once decrypted, the payload is stored as a DLL in the AppData and executed via scheduled tasks every 13 minutes, ensuring a persistent presence on the system, even after reboots.
At the same time, communication is done with custom JSON encoding and non-standard Base64 alphabet, making network analysis.
A threat that requires increased vigilance
OysterLoader demonstrates how sophisticated modern malware loaders have become. Its connection to ransomware ecosystems, use of steganography, and anti-analysis techniques make it one of the most dangerous infection mechanisms of our time.
For organizations and users, being careful with downloads, using trusted sources, and strengthening cyber defenses is now more necessary than ever.
