Masked hackers with shields and locks surrounding laptop displaying code with data streams and envelopes

Daily Dose of Cybersecurity News - September 28, 2025

Fake Microsoft Teams Installers Distribute Oyster Malware via Malvertising

High

What happened

Attackers are using search engine optimization (SEO) poisoning and malicious advertisements to promote counterfeit Microsoft Teams installers. These fake installers infect Windows devices with the Oyster backdoor, granting unauthorized remote access to compromised systems.

Who is affected

Organizations and individuals seeking to download Microsoft Teams are at risk, especially those who access the application through search engine results or online advertisements.

Why it matters

The Oyster malware enables attackers to execute commands, deploy additional payloads, and transfer files on infected devices. This can lead to data breaches, system compromises, and potential ransomware attacks, posing significant threats to organizational security.

How it could have been prevented

- Always download software from official and verified sources. - Implement endpoint protection solutions to detect and block malicious software installations.

Relevant professional terms

SEO Poisoning
Manipulating search engine results to promote malicious websites or content.
Malvertising
The use of online advertising to spread malware by embedding malicious code within ads.

Recommended reading: Arctic Wolf: Malvertising Campaigns Impersonate Popular IT Tools to Distribute Oyster Backdoor

China-Linked PlugX and Bookworm Malware Attacks Target Asian Telecom and ASEAN Networks

High

What happened

Chinese state-sponsored threat actors have launched cyber attacks targeting telecommunications and manufacturing sectors in Central and South Asia, deploying new variants of the PlugX and Bookworm malware to infiltrate and control compromised systems.

Who is affected

Telecommunications and manufacturing companies in Central and South Asian countries, as well as nations affiliated with the Association of Southeast Asian Nations (ASEAN).

Why it matters

These attacks highlight the persistent threat posed by Chinese APT groups to critical infrastructure sectors, emphasizing the need for enhanced cybersecurity measures to protect sensitive information and maintain operational integrity.

How it could have been prevented

Implementing robust endpoint detection and response (EDR) solutions, conducting regular security audits, and ensuring timely patching of software vulnerabilities can mitigate the risk of such sophisticated attacks.

Relevant professional terms

Advanced Persistent Threat (APT)
A prolonged and targeted cyber attack in which an intruder gains access to a network and remains undetected for an extended period.
Remote Access Trojan (RAT)
A type of malware that allows a remote operator to control a system as if they had physical access to it.

Recommended reading: unit42.paloaltonetworks.com