Malware

Broomstick

Also known as: CLEANBOOST · CleanUp · CleanUpLoader · Oyster

Oyster is a backdoor malware written in C++ that first appeared in July 2023. It allows for remote sessions, supporting tasks such as file transfer and command-line processing. This malware has been used by numerous threat actors as a tool to facilitate ransomware intrusions. The distribution of Oyster has likely occurred through various methods, as suggested by the build identifiers found in examined samples. Additionally, Oyster is capable of collecting basic system data and communicates with a command-and-control (C2) server. It can execute commands via cmd.exe and run additional files. In August 2024, a new version of Oyster was discovered that featured a new command-and-control (C2) communication protocol format. This 2024 version contained plaintext strings and lacked code obfuscation, suggesting it was still in development. In contrast to the 2024 version, the new 2025 Oyster version does not send C2 messages in plaintext, instead reintroducing the substitution cipher that was present in earlier versions of Oyster.

Indicators of Compromise 12

MITRE ATT&CK TTPs 24

Source Articles

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Unit42 analyzed 405 AI-enabled malware samples and found that only 12 were observed in production environments, indicating that most such malware remains in proof-of-concept or testing stages. The operational threats included FunkSec ransomware, a trojanized AI application (Recipe Lister), the Oyster backdoor, Rhadamanthys stealer, and a COM hijacking DLL. These threats used techniques such as code signing abuse, DLL side-loading, and social engineering leveraging AI branding. All were detected and blocked by existing defenses including sandboxing, behavioral analytics, and cloud-based verdicts, with no novel detection methods required.
unit42 ·1w ago
IT threat evolution in Q2 2026. Non-mobile statistics
In Q2 2026, multiple ransomware groups remained active, with Qilin emerging as the most prolific based on victims listed on data leak sites. Microsoft disrupted a malware-signing-as-a-service operation run by the threat actor Fox Tempest, which was used by several ransomware groups including Rhysida, Akira, and Qilin. CISA added a Windows local privilege escalation vulnerability (CVE-2026-33825, BlueHammer) to its KEV catalog due to active exploitation in ransomware attacks. Check Point attributed zero-day exploitation of a critical vulnerability in its Remote Access VPN (CVE-2026-50751) to the Qilin ransomware group. Additionally, the PayoutsKing group was observed using QEMU to deploy hidden Alpine Linux-based virtual machines as a stealthy backdoor technique.
securelist ·3w ago