A sophisticated malvertising campaign leveraging SEO poisoning techniques has been intensifying through July 2025, with researchers from Arctic Wolf and CyberProof warning organizations of the resurgence and evolution of the Oyster backdoor (also known as Broomstick or CleanupLoader).
The Oyster malware family has previously masqueraded as installers for widely used tools, but the latest wave specifically targets IT administrators and power users by impersonating trusted programs like PuTTY, KeyPass, and WinSCP through rigged web searches and malicious sponsored ads.
Technical Analysis
The typical attack begins with users searching for popular IT tools via search engines such as Google or Bing. Through clever manipulation of search results, attackers distribute links to deceptive websites hosting trojanized installers, often piggybacking on malvertising infrastructure.
Notably, one campaign involved a fake PuTTY installer “PuTTY-setup.exe” downloaded from danielaurel.tv, which was discovered and investigated in a controlled sandbox environment (ANY.RUN).
The installer, signed with a revoked certificate, was not only designed to allay suspicion but also complicate network-based detection and trust validation processes.

Upon execution, the installer dropped a malicious DLL payload often referenced as “zqin.dll” that was manually invoked using rundll32.exe.
This is a hallmark technique for loader-style malware, allowing the backdoor to evade conventional static detection and seamlessly integrate into legitimate system processes.
Analysts confirmed the persistence mechanism involved creating a scheduled task (“FireFox Agent INC”) configured to trigger every three minutes.
This persistence not only ensured regular execution of the malicious DLL but also made the infection resilient against reboots and session changes.

The Oyster backdoor is engineered to afford attackers substantial control over the compromised endpoint.
Its capabilities include harvesting system and user credentials, executing arbitrary commands, downloading additional malware, and exfiltrating sensitive data.
CyberProof’s incident review indicated that, while an infection attempt did reach the execution stage, robust endpoint detection and response tools were able to identify and stop the backdoor before attackers could escalate privileges or engage in hands-on-keyboard activity.
Use of Revoked Certificates Increases Stealth
Analysts have observed an uptick in the abuse of revoked code signing certificates to sign these fake installers.
This increasingly common malware evasion tactic is not limited to the current Oyster campaign, as seen in other operations involving remote management tool droppers like ConnectWise ScreenConnect.
Revoked certificates are used as a means of bypassing basic trust checks since some security controls only verify signature presence, not validity thus heightening the risk for organizations with less mature endpoint validation processes.
Oyster backdoor infections are not merely isolated breaches. Prior reports have linked Oyster-compromised systems to subsequent ransomware activity, including deployment of high-profile families like Rhysida.
As initial access facilitators, loaders such as Oyster provide threat actors with a launching platform for full-scale network intrusions, lateral movement, and data exfiltration.
Security experts recommend that organizations especially those with IT staff and administrators strictly avoid downloading utility executables from ad links or third-party search results. Relying on vetted, internal software repositories or strictly official vendor sites is essential.
Vigilant monitoring for the tactics outlined in this campaign, such as persistent scheduled tasks and anomalous DLL side-loading, remains a critical component of effective defense-in-depth against ongoing malvertising threats.
Indicators of Compromise (IOC)
| Indicator Type | Value / Description |
|---|---|
| Domain | updaterputty[.]com |
| Domain | zephyrhype[.]com |
| Domain | putty[.]run |
| Domain | putty[.]bet |
| Domain | puttyy[.]org |
| Hash (SHA256) | a8e9f0da26a3d6729e744a6ea566c4fd4e372ceb4b2e7fc01d08844bfc5c3abb |
| Hash (SHA256) | 3654c9585f3e86fe347b078cf44a35b6f8deb1516cdcd84e19bf3965ca86a95b |
| Hash (SHA256) | 3d22a974677164d6bd7166e521e96d07cd00c884b0aeacb5555505c6a62a1c26 |
| File Name | PuTTY-setup.exe, Zqin.dll |
| IP Address | 194.213.18.89 |
| IP Address | 85.239.52.99 |
| Downloaded URL | https[:]//danielaurel.tv/wp-json/api/download/553d53f6d17341fb5a4acdd48f2a0152 |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates