Threat Actors Leverage SEO Poisoning and Malicious Ads to Distribute Backdoored Microsoft Teams Installers

A new campaign is distributing the Oyster (Broomstick) backdoor through trojanized Microsoft Teams installers. Threat actors are using SEO poisoning and malvertising to trick users into downloading fake installers from spoofed websites. The malicious installers deploy a persistent backdoor that enables remote access, gathers system information, and supports additional payload delivery while evading detection. This tactic mirrors earlier fake PuTTY campaigns, showing a trend of abusing trusted software for initial access. The backdoor communicates with attacker-controlled C2 domains and uses DLL sideloading via rundll32.exe for stealthy execution. Organizations are advised to download software only from verified sources and avoid relying on search engine advertisements.

Pulse ID: 68de52ef382d67c8bdc97094
Pulse Link: https://otx.alienvault.com/pulse/68de52ef382d67c8bdc97094
Pulse Author: AlienVault
Created: 2025-10-02 10:24:47

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#BackDoor #CyberSecurity #InfoSec #MaliciousAds #Malvertising #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #RCE #Rust #SEOPoisoning #SideLoading #Trojan #Troll #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

🚨 Big change coming to Android 🚨

Google is rolling out Developer Verification — every app on certified devices must be tied to a verified ID.

Google says it’s about stopping scams. Critics say it could kill alt stores like F-Droid and choke indie devs.

Security or control?

https://dropletdrift.com/google-developer-verification-is-about-safety/

#Android #Google #FOSS #Apps #OpenSource #Privacy #Security #Developers #Tech #Software #Mobile #BigTech #Competition #Monopoly #Freedom #DigitalRights #Sideloading #PlayStore #Regulation

Google: developer verification is about safety - DropletDrift

Google has published a Q&A that tries to calm a developer community worried about its new identity requirement for anyone who wants their Android apps to install on certified devices. The company frames ā€œdeveloper verificationā€ as a simple idea. If you install an app, your phone should know that the person behind it is who […]

DropletDrift
Google stellt klar: Sideloading auf Android bleibt erhalten | heise online
https://heise.de/-10688904 #Android #Sideloading #FDroid

Planowana nowa funkcja bezpieczeństwa w przeglądarce Edge

W czwartek w harmonogramie Microsoft 365 pojawiła się nowa aktualizacja dla przeglądarki Edge z wdrożeniem planowanym na listopad 2025. Nowa funkcja bezpieczeństwa ma chronić użytkowników przed złośliwymi rozszerzeniami instalowanymi ręcznie (tzw. sideloading). Edge umożliwia deweloperom lokalne instalowanie rozszerzeń w celu testowania przed opublikowaniem ich w sklepie Microsoft Edge Add-ons. Ta...

#WBiegu #Aktualizacja #Awareness #Edge #Microsoft #Rozszerzenia #SideLoading

https://sekurak.pl/planowana-nowa-funkcja-bezpieczenstwa-w-przegladarce-edge/

Planowana nowa funkcja bezpieczeństwa w przeglądarce Edge

W czwartek w harmonogramie Microsoft 365 pojawiła się nowa aktualizacja dla przeglądarki Edge z wdrożeniem planowanym na listopad 2025. Nowa funkcja bezpieczeństwa ma chronić użytkowników przed złośliwymi rozszerzeniami instalowanymi ręcznie (tzw. sideloading). Edge umożliwia deweloperom lokalne instalowanie rozszerzeń w celu testowania przed opublikowaniem ich w sklepie Microsoft Edge Add-ons. Ta...

Sekurak
If Google is killing sideloading, then Android is just iOS with ads and spyware. Why the hell would anyone choose that?
https://fireborn.mataroa.blog/blog/why-the-hell-does-android-even-exist-anymore/
#Android #Google #Sideloading #FOSS #Privacy #accessibility
Why the Hell Does Android Even Exist Anymore? — fireborn

top gaslighting from Google - and not addressing the original F-Droid concerns.

in a way, this approach is even worse than Apple because at least Apple doesn't pretend to care about openness of a system.

https://android-developers.googleblog.com/2025/09/lets-talk-security-answering-your-top.html

#Privacy #Android #Google #FDroid #Sideloading

Let's talk security: Answering your top questions about Android developer verification

News and insights on the Android platform, developer tools, and events.

Android Developers Blog

This is turning out to be one of the worst moves that Android has ever made.

F-Droid says Google’s new sideloading restrictions will kill the project

https://arstechnica.com/gadgets/2025/09/f-droid-calls-for-regulators-to-stop-googles-crackdown-on-sideloading/

#FDroid #Google #Sideloading #Android #OpenSource #Tech

F-Droid and Google's Developer Registration Decree | F-Droid - Free and Open Source Android App Repository

For the past 15 years, F-Droidhas provided a safe and secure haven for Android users around the world tofind and install free and open source apps. When cont...

4/7 If you own a computer, you should have the unquestionable right to run the programs you want on it. Google’s attempt to strip this right is as absurd as forcing writers to register with a central authority before publishing. It’s an assault on free expression and innovation.

#BigTech #Sideloading #UserFreedom

F-Droid accusa Google di minare la libertĆ  digitale con la nuova politica anti-sideloading. Il software libero ĆØ sotto pressione. #FDroid #Google #Sideloading #Antitrust #OpenSource

https://www.linuxeasy.org/f-droid-contro-google-android/?utm_source=mastodon&utm_medium=jetpack_social

F-Droid contro Google: la libertĆ  di installare app ĆØ a rischio

F-Droid critica duramente la nuova politica anti-sideloading di Google, denunciando una minaccia alla libertĆ  digitale e chiedendo un intervento antitrust.

Linux Easy