Putty, Teams Ads Used to Spread Rhysida Ransomware
Cybercriminals are using deceptive online ads to disguise malware as legitimate software like PuTTY and Microsoft Teams, in a campaign known as Putty Teams Ads Spread. The effort delivers OysterLoader, a stealthy tool that enables intrusions into corporate networks and serves as an entry point for the Rhysida ransomware group.
Researchers at Expel uncovered this campaign, which mirrors tactics used during a similar operation from mid-2024. Since June 2025, activity has escalated, with attackers purchasing Bing ads that lead users to fake download pages for popular apps. These include misspelled listings like “Putty,” which appear even within Windows 11’s start menu.
OysterLoader’s success relies on two key methods: obfuscation and abuse of code-signing certificates. Security tools often fail to detect the malware in its early stages. Rhysida has also deployed Latrodectus malware and exploited Microsoft’s Trusted Signing to bypass certificate limits.
Read the full report here:
Weaponized Putty and Teams Ads Deliver Malware Allowing Hackers to Access Network
