A notorious ransomware group is spreading fake Microsoft Teams ads to snare victims. Search engine users should be cautious about downloading Microsoft Teams, as the Rhysida ransomware group is using fake ads to distribute malware. Cybersecurity firm Expel discovered an ongoing malicious ad campaign delivering a malware called OysterLoader, previously known as Broomstick and CleanUpLoader. This is the group's second campaign to impersonate the workplace collaboration platform in the last eighteen months. OysterLoader is an initial access tool (IAT) that, once downloaded, runs a backdoor to gain long-term access to the device and network. The current infection chain is built on a highly successful malvertising model, where threat actors buy Bing search engine advertisements to direct users to convincing-looking, but malicious landing pages. These search engine ads put links to the download right in front of potential victims. The group uses a packing tool that effectively hides the capabilities of the malware and results in a low static detection rate when the malware is first seen. They also use code-signing certificates, as used by genuine software publishers, to give their own malicious files a higher level of trust. Notably, this helped Expel detect the campaign. Rhysida is ramping up attacks, using both OysterLoader and Latrodectus malware to gain initial access to networks. Rhysida ranks among one of the few cyber criminal groups to be leveraging Trusted Signing from Microsoft, the company’s own service for issuing code-signing certificates. Attackers are using Trusted Signing certificates for both OysterLoader and Latrodectus and appear to have found a way around the built-in features designed to limit misuse. Rhysida first appeared as Vice Society in 2021, but rebranded as Rhysida in 2023, and operates on a Ransomware as a Service (RaaS) double extortion model. Since 2023, the group has posted around 200 victims on its data leak site, including governments, healthcare organizations, and critical infrastructure industries. Earlier this year, the group claimed responsibility for attacks on the Oregon Department of Environmental Quality, the Cookville Regional Medical Center in Tennessee, Sunflower Medical Group in Kansas, and the Community Care Alliance, a mental illness and addiction group. The group also hit the Maryland Department of Transportation and the British Library. Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews. MORE FROM ITPRO * How hackers bypass MFA – and what to do about it * Hackers are disguising malware as ChatGPT, Microsoft Office, and Google Drive to dupe workers * Ransomware victims are refusing to play ball with hackers
Rhysida Ransomware: Fake Microsoft Teams Ads & OysterLoader Malware Explained (2025)
References
- https://lbbonline.com/news/Aldi-UK-Haunting-Middle-Aisle
- https://payloadspace.com/uksa-taps-slingshot-for-sda-tech/
- https://www.gamesindustry.biz/switch-2-reaches-highest-global-sales-of-any-nintendo-platform-in-first-four-months-of-launch
- https://www.itpro.com/security/cyber-attacks/a-notorious-ransomware-group-is-spreading-fake-microsoft-teams-ads-to-snare-victims
- https://www.businesswire.com/news/home/20251105077892/en/Nissan-and-Infobip-Achieve-200-Increase-in-Engagement-with-AI-Driven-WhatsApp-Campaign
- https://www.business-standard.com/technology/tech-news/openai-acquires-software-applications-ai-startup-by-ex-apple-engineers-behind-workflow-shortcuts-125102400825_1.html
Top Articles
Houston Rockets Dominate Brooklyn Nets for First Win of the Season | NBA Highlights & Analysis
Wrexham vs Cardiff (1-2) Carabao Cup 2025: Full Match Analysis & Highlights | Will Fish's Stunner!
Poet Laureate Celebrates 50 Years of Pink Floyd's Wish You Were Here
Latest Posts
Hornets vs Heat Score Prediction: Can Charlotte Beat Miami in NBA Opener?
Google's Pomelli AI: Revolutionizing Brand Promotions for SMBs
Recommended Articles
- Belgrade Protests: The Story Behind the Fight for a Historic Site
- Mathematician Wu Meng's Breakthrough: Solving Furstenberg's Conjecture
- Dodgers Eye Devin Williams After Yankees Struggles: Is He the Missing Piece?
- NTT DATA: 5G Engineering Services Leader | 2025 Everest Group Report
- Gisborne Murder: CCTV Footage of Suspects Released
- Are Muni ETFs tax-exempt?
- Govinda Hospitalized: Bollywood Star Loses Consciousness at Home
- Meet Pedro, the Louvre Heist 'Detective' Inspired by Poirot & James Bond | Vintage Fashion Icon
- Cameroon's Post-Election Crisis: Killings, Mass Arrests, and Human Rights Abuses
- Jimmy Kimmel's Emotional Tribute to His Late Bandleader & Best Friend, Cleto Escobedo III
- EU's AI Election Interference Fight: Deepfakes & Chip Scarcity!
- Cameroon's Post-Election Crisis: Killings, Mass Arrests, and Human Rights Abuses
- PANAP Mentorship Programme 2025-2026: Research Opportunities for African Early-Career Researchers
- Loewe's Grand Entrance: Exploring the New Casa Loewe on Avenue Montaigne!
- Blackpool Council: Unsustainable Private Children's Care Costs - Exploring Alternatives
- Feng Shui Secrets: 10 Common Household Items Draining Your Energy
- Latvia Weather Update: Sunshine Breaks Through Clouds on Wednesday
- SoftBank's Shocking Nvidia Sale: AI Sector Impact and Market Reaction
- Rockies' Paul DePodesta: Fixing Historically Bad Starting Pitching Through Trades & Creative Moves
- Eric Garcia: Barcelona's Masked Hero - From Outcast to Indispensable Leader
- Govinda Hospitalized: Bollywood Star Loses Consciousness at Home
- The Unsung Hero: Arundhati Reddy's Journey to World Cup Glory
- Blackpool Council: Unsustainable Private Children's Care Costs - Exploring Alternatives
- Blackpool Council: Unsustainable Private Children's Care Costs - Exploring Alternatives
- SoftBank's Shocking Nvidia Exit: What Investors Need to Know!
- NTT DATA: 5G Engineering Services Leader | 2025 Everest Group Report
- Indigenous Protesters Storm COP30 in Brazil: A Call for Action
- Art Market Trends: Insights from the Fall Art Fair Frenzy
- Online Literature Adaptations: The Gold Mine for Chinese Screen Content
- Unlocking Namibia's Informal Economy: A $13 Billion Opportunity
- Vietnam's Credit Boom: Risks & Rollback of Quotas Explained | Fitch Ratings Warning
- Ben Stokes Defends England's Ashes Prep: Is It Madness or Smart Strategy?
- Gisborne Murder: CCTV Footage of Suspects Released
- China's Central Bank: A Shift in Monetary Policy
- England's Top 8 Wins Over the All Blacks: A Rugby History
- Healthcare Funding Crisis: What's Next for South Africa's NHI?
- Jimmy Kimmel's Emotional Tribute to His Late Bandleader & Best Friend, Cleto Escobedo III
- Booking.com's David Adamczyk on AI, Vibes, and the Future of Connected Travel | WiT Studio Interview
- China's Central Bank: A Shift in Monetary Policy
- Namibia's Land Bill: Unveiling the Need for a Comprehensive Land Audit
- NBA All-Star Game Format Tweak: USA vs. World Format Announced
- Dodgers Eye Devin Williams After Yankees Struggles: Is He the Missing Piece?
- Uncovering Japan's Hidden Gem: Olive Hill, a Budget Italian Paradise
- Namibia's Land Bill: Unveiling the Need for a Comprehensive Land Audit
- Howard Jones Plays on £450,000 Steinway Spirio R Automated Piano - Live Spiriocast Event
- Blackpool Council: Unsustainable Private Children's Care Costs - Exploring Alternatives
- PANAP Mentorship Programme 2025-2026: Research Opportunities for African Early-Career Researchers
- Chris Ellison's Billionaire Comeback: Unlocking Lithium's Potential
- Eric Garcia: Barcelona's Masked Hero - From Outcast to Indispensable Leader
- Chris Ellison's Billionaire Comeback: Unlocking Lithium's Potential
- SoftBank's Shocking Nvidia Exit: What Investors Need to Know!
- Northern Lights in Florida: Epic Auroras from Solar Storm!
- Dodgers Eye Devin Williams After Yankees Struggles: Is He the Missing Piece?
- Mathematician Wu Meng's Breakthrough: Solving Furstenberg's Conjecture
- Jellycat Ski Club at The Grove: A Whimsical Winter Wonderland in L.A.!
- Namibia's Land Bill: Unveiling the Need for a Comprehensive Land Audit
- Blackpool Council: Unsustainable Private Children's Care Costs - Exploring Alternatives
- PANAP Mentorship Programme 2025-2026: Research Opportunities for African Early-Career Researchers
- Namibia's Land Bill: Unveiling the Need for a Comprehensive Land Audit
- Onassis ONX: Massive Art & Tech Studio in NYC | Tech & Art News
- Gerrit Cole Injury Update: Yankees Ace's Return Timeline & Opening Day Status!
- Northern Lights in Florida: Epic Auroras from Solar Storm!
- PBOC Changes Course: Goldman Sachs Predicts Extended Easing Pause
- China Bridge Collapse: Sichuan's Hongqi Bridge Crumbles into River
- Google's Gemini AI: Privacy Invasion or Innovation?
- Now You See Me: Now You Don’t - Louvre Heist Conspiracy Theory with Cast Reactions!
- Blackpool Council: Unsustainable Private Children's Care Costs - Exploring Alternatives
- IVE's Wonyoung Buys $10M Luxury House Linked to Her Chaebol Bestie!
- Meet Pedro, the Louvre Heist 'Detective' Inspired by Poirot & James Bond | Vintage Fashion Icon
- Michael Phelps' Stunning Transformation: From Olympic Swimmer to Bearded Man Bun Icon
- Anne Hathaway's Retro Birthday Dress: Reviving the Underwear as Outerwear Trend
- The Unsung Hero: Arundhati Reddy's Journey to World Cup Glory
- Howard Jones Plays on £450,000 Steinway Spirio R Automated Piano - Live Spiriocast Event
- Chris Ellison's Billionaire Comeback: Unlocking Lithium's Potential
- Jimmy Kimmel's Emotional Tribute to Cleto Escobedo III: A Lifetime of Friendship & Music
- Dharmendra's International Fan: When Nawaz Sharif Stopped by His House
- Injury Scares: Hazlewood & Abbott's Hamstring Scans Ahead of the Ashes
- Flight Disruptions: Airlines Warn of Delayed Recovery Post-Shutdown
- Australia's Most Powerful Battery: Catastrophic Failure or High Cycling Issue?
- Blackpool Council: Unsustainable Private Children's Care Costs - Exploring Alternatives
- Gisborne Murder: CCTV Footage of Suspects Released
- Steph Curry's First Career Flagrant Foul: A Rare Occurrence for the NBA Legend
- Musetti's Epic Comeback! ATP Finals Thriller vs. De Minaur | 'Fino Alla Fine'
- Govinda Hospitalized: Bollywood Star Loses Consciousness at Home
- NTT DATA Named a Leader in 5G Engineering Services by Everest Group 2025 | Private 5G & AI Solutions
- Gisborne Murder: CCTV Footage of Suspects Released
- Cameroon's Post-Election Crisis: Killings, Mass Arrests, and Human Rights Abuses
- Govinda Hospitalized: Bollywood Star Loses Consciousness at Home
- Police Assault: 7 Charged After Violent Incident in NSW
- Dies Irae Box Office Collection Day 13: Strong Start, But What's Next?
- Anne Hathaway's Iconic Birthday Dress: Underwear as Outerwear Trendsetter
- Abu Dhabi Launches First Vertiport Network for Advanced Air Mobility
- Cameroon's Post-Election Crisis: Killings, Mass Arrests, and Human Rights Abuses
- SoftBank's Shocking Nvidia Sale: AI Sector Impact and Market Reaction
- Timor-Leste's Greater Sunrise Project: Investment Opportunities & ASEAN Partnership
- Namibia's Land Bill: Unveiling the Need for a Comprehensive Land Audit
- Police Assault: 7 Charged After Violent Incident in NSW
- Dodgers Eye Devin Williams After Yankees Struggles: Is He the Missing Piece?
- Loewe's Grand Entrance: Exploring the New Casa Loewe on Avenue Montaigne!
- Howard Jones Plays on £450,000 Steinway Spirio R Automated Piano - Live Spiriocast Event
Article information
Author: Reed Wilderman
Last Updated:
Views: 5793
Rating: 4.1 / 5 (52 voted)
Reviews: 83% of readers found this page helpful
Author information
Name: Reed Wilderman
Birthday: 1992-06-14
Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877
Phone: +21813267449721
Job: Technology Engineer
Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti
Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.