Broomstick

Aliases: CLEANBOOST, CleanUp, CleanUpLoader, Oyster

First seen
2023-07-01 00:00:00
Malware type
backdoor, ransomware
Family
Malware family
Last IoC activity
2026-07-21 23:08:47
Profile updated
2026-07-07 14:29:26

Targeted industries: financial-services technology-and-telecommunications healthcare-and-pharmaceutical

Context

Oyster is a backdoor malware written in C++ that first appeared in July 2023. It allows for remote sessions, supporting tasks such as file transfer and command-line processing. This malware has been used by numerous threat actors as a tool to facilitate ransomware intrusions. The distribution of Oyster has likely occurred through various methods, as suggested by the build identifiers found in examined samples. Additionally, Oyster is capable of collecting basic system data and communicates with a command-and-control (C2) server. It can execute commands via cmd.exe and run additional files. In August 2024, a new version of Oyster was discovered that featured a new command-and-control (C2) communication protocol format. This 2024 version contained plaintext strings and lacked code obfuscation, suggesting it was still in development. In contrast to the 2024 version, the new 2025 Oyster version does not send C2 messages in plaintext, instead reintroducing the substitution cipher that was present in earlier versions of Oyster.

Detection coverage

  • 7 YARA rules

Detection rules

  • RUSSIANPANDA_Mal_Cleanuploader (yara-rule)
  • SEKOIA_Backdoor_Oyster (yara-rule)
  • SIGNATURE_BASE_MAL_Emotet_BKA_Cleanup_Apr21 (yara-rule)
  • SIGNATURE_BASE_LOG_Exchange_Forensic_Artefacts_Cleanup_Activity_Mar21_1 (yara-rule)
  • SIGNATURE_BASE_SUSP_BAT_Aux_Jan20_1 (yara-rule)
  • CAPE_Oyster (yara-rule)
  • MALPEDIA_Win_Broomstick_Auto (yara-rule)

Reports & references

  • go.recordedfuture.com — Cta 2025 0130 (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Broomstick (report)
  • rapid7.com — Malvertising Campaign Leads To Execution Of Oyster Backdoor (report)
  • expel.com — Certified Oysterloader Tracking Rhysida Ransomware Gang Activity Via Code Signing Certificates (report)
  • levelblue.com — Like Putty In Admins Hands (report)
  • Broadcom/Symantec — Malware Ai Llm (report)
  • hunt.io — Oysters Trail Resurgence Infrastructure Ransomware Cybercrime (report)
  • go.recordedfuture.com — Cta 2024 1009 (report)
  • redcanary.com — Intelligence Insights July 2025 (report)
  • exchange.xforce.ibmcloud.com — Guid:2F96Dded08Ec1C2Dd039Fca21378050C (report)
  • hunt.io — A Simple Approach To Discovering Oyster Backdoor Infrastructure (report)
  • blog.sekoia.io — Oysterloader Unmasked The Multi Stage Evasion Loader (report)
  • reversinglabs.com — Unpacking Pkr Mtsi (report)
  • malasada.tech — Oyster Malware Delivery Via Teams Fake App (report)
  • blackpointcyber.com — Malicious Teams Installers Drop Oyster Malware (report)
  • exchange.xforce.ibmcloud.com — Guid:Df2B52D89C5C0Edfdf7Bdaa6F67Dd714 (report)
  • threatdown.com — Rhysida Using Oyster Backdoor To Deliver Ransomware (report)

External references