Cyber Security News

Oyster Malware as PuTTY, KeyPass Attacking IT Admins by Poisoning SEO Results

The Oyster malware, also known as Broomstick or CleanupLoader, has resurfaced in attacks disguised as popular tools like PuTTY, KeyPass, and WinSCP.

This malware, active since at least 2023, tricks users into downloading malicious installers, potentially paving the way for ransomware infections such as Rhysida.

CyberProof Threat Researchers recently uncovered a real-world instance in the second half of July 2025, where an unsuspecting user was lured into installing a fake PuTTY executable.

The attack was swiftly detected and blocked by security measures, preventing any hands-on keyboard activity from intruders. This incident highlights the persistent danger of SEO poisoning, where attackers manipulate search rankings to promote malicious sites mimicking legitimate software downloads.

The campaign begins with users searching for tools like PuTTY. Poisoned results lead to domains such as updaterputty[.]com, putty[.]run, or putty[.]bet, which host fake installers.

Attack Flow

In the observed case, the malicious file named PuTTY-setup.exe with SHA256 hash a8e9f0da26a3d6729e744a6ea566c4fd4e372ceb4b2e7fc01d08844bfc5c3abb was downloaded from danielaurel[.]tv.

Once executed, the installer drops a malicious DLL file, zqin.dll, and runs it via rundll32.exe. This establishes the Oyster backdoor, which collects system information, steals credentials, executes commands, and downloads additional malware, reads the report.

Persistence is achieved through a scheduled task called “FireFox Agent INC,” set to run every three minutes, ensuring the malware remains active even after reboots.

Notably, the installer used a revoked digital certificate, a tactic seen in other recent campaigns like those abusing ConnectWise ScreenConnect.

VirusTotal scans revealed multiple files signed with the same revoked certificate, indicating a broader operation. Proxy logs from the incident showed the user visiting SEO-poisoned sites, confirming the deception.

Oyster campaigns have evolved from impersonating Google Chrome and Microsoft Teams to targeting IT-specific tools, exploiting admins’ trust in familiar software. Arctic Wolf first reported similar malvertising in early June 2025, linking it to trojanized installers that deliver the backdoor. These loaders often facilitate ransomware, as seen with Rhysida deployments.

For IT admins, the risk is acute: a single poisoned search can compromise entire networks. In the CyberProof case, sandbox analysis on Any.Run confirmed the file’s malicious behavior, including DLL execution and task scheduling. No further exploitation occurred due to timely detection, but the potential for data theft or ransomware remains high.

Indicators of Compromise (IoCs) for Oyster Backdoor

Indicator TypeIndicator
Domainupdaterputty[.]com
Domainzephyrhype[.]com
Domainputty[.]run
Domainputty[.]bet
Domainputtyy[.]org
IP Address194.213.18.89
IP Address85.239.52.99
File Hash3d22a974677164d6bd7166e521e96d07cd00c884b0aeacb5555505c6a62a1c26
File Hasha8e9f0da26a3d6729e744a6ea566c4fd4e372ceb4b2e7fc01d08844bfc5c3abb
File Hash3654c9585f3e86fe347b078cf44a35b6f8deb1516cdcd84e19bf3965ca86a95b
File NameZqin.dll

To mitigate, organizations should educate users on verifying downloads, enable multi-factor authentication, and deploy endpoint detection tools. Regularly hunting for suspicious scheduled tasks and monitoring for revoked certificates can help. As SEO poisoning surges, staying vigilant against these deceptive tactics is crucial for safeguarding IT environments.

Experience faster, more accurate phishing detection and enhanced protection for your business with real-time sandbox analysis-> Try ANY.RUN now

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

16 seconds ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

6 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

17 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago