Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. A counterfeit software-download page can persuade you to run an installer that delivers malware, including a backdoor. In campaigns reported in 2024, attackers used fake downloads for popular apps to spread Oyster, also known as Broomstick. Later reporting described fake PuTTY and WinSCP installers. A separate Microsoft report from September 2026 documents another counterfeit-download campaign, but does not identify it as Oyster.

How a fake download can become a backdoor infection

Attackers can buy ads or manipulate search results so that a counterfeit page appears when someone looks for a familiar application. The page may copy the vendor’s branding and offer what looks like a normal installer. But a familiar app name, polished design, high search ranking, or sponsored placement does not establish that the site or download is genuine.

The risk comes when a person runs the downloaded installer. It may install or launch malicious code alongside—or instead of—the expected application. A program opening successfully is not proof that the installer was safe.

What the Oyster reports describe

Fake Chrome and Teams downloads in 2024

Rapid7’s June 17, 2024 report summarized a malvertising campaign that targeted people searching for software downloads and used malicious installers posing as Google Chrome and Microsoft Teams. Rapid7 identified the malware as Oyster and noted that IBM had used the name Broomstick. The available campaign summary supports the delivery and lure details; it does not establish sample hashes, exact command-and-control behavior, or a broader set of technical indicators.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Fake PuTTY and WinSCP downloads

An Eventus Security advisory later described SEO poisoning and malvertising promoting fake PuTTY and WinSCP downloads associated with Oyster/Broomstick. It reported scheduled-task persistence and said endpoint detection prevented connections in cases covered by the advisory. The advisory does not provide a clear publication date or identify a responsible actor, so neither a campaign date nor an attribution should be inferred from it.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How the reports differ

Counterfeit downloads recur as a delivery method, but that does not make every campaign an Oyster campaign. Microsoft’s September 1, 2026 report is useful context for the wider threat; it does not name Oyster.

Reporting Lure and delivery Reported scope or audience Post-execution behavior Attribution
Rapid7, June 17, 2024 Malvertising and fake Google Chrome and Microsoft Teams installers aimed at software-download searches. People searching for software downloads; further scope not stated in the campaign summary. Not stated in the campaign summary. Identifies Oyster and notes IBM’s Broomstick name; responsible actor not stated in the summary.
Eventus Security advisory; publication date not stated SEO poisoning, malvertising, and fake PuTTY and WinSCP downloads. Not stated. Scheduled-task persistence; the advisory says endpoint detection prevented connections in cases it summarized. Not stated; the advisory’s threat-actor fields are blank.
Microsoft Security Research, Microsoft Defender Experts, and Parth Jomadkar, September 1, 2026 Spoofed software-vendor pages and counterfeit installers; some delivery used archives and wrappers. Observed across organizations and sectors, predominantly in China-based operations and among Chinese-speaking users. Reported sectors included healthcare, manufacturing, gaming, technology, logistics, government, and higher education. Scheduled tasks, attempts to add broad Defender exclusions, shadow-copy deletion, Windows Update tampering, process injection, and outbound command-and-control attempts. Microsoft assessed the activity as moderately consistent with publicly reported Silver Fox/Yinhu activity, but said it had not attributed it to a nation-state actor. It did not call the campaign Oyster.

What Microsoft’s 2026 campaign adds—and what it does not

Microsoft described counterfeit pages impersonating brands including Razer, Microsoft Edge, Kaspersky, Sejda PDF, NetEase Youdao Dictionary, DiskGenius, Baidu Netdisk, oCam, draw.io, SteelSeries, Sogou, Calibre, and MindMaster. The pages funneled users to shared delivery infrastructure. Microsoft also observed archives whose contents changed between downloads even when the delivery URL stayed the same, consistent with server-side payload generation.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Microsoft’s investigators wrote: “Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers.” That statement describes the campaign in Microsoft’s report, not an explicit Oyster attribution. The persistence and security-tampering behaviors in the table are likewise Microsoft’s observations from that campaign, not established properties of every Oyster sample.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Microsoft’s report lists affected sectors but does not provide a victim count or percentage in the material summarized here. No reliable Oyster-specific infection total or prevalence estimate is established by the cited reporting. HP Wolf Security’s October–December 2025 dataset found that executable files made up 37% of email threat delivery types, ZIP files 11%, and DOCX files 10%; those are email-delivery figures, not estimates of Oyster infections or counterfeit-download prevalence.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

How to check whether a download is genuine

  • Navigate to the software maker’s known official website rather than choosing an ad or an unfamiliar search result.
  • Check the domain itself, not just the page’s logo, app name, or search ranking.
  • Prefer the vendor’s own installer or an organization-managed software catalog over a third-party download portal when available.
  • Do not treat a valid-looking digital signature or an application that opens successfully as proof that the download is safe.
  • If an installer appears unexpectedly or you are unsure about its source, do not run it; ask your organization’s IT or security team if the device is managed.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if you ran a suspicious installer

On a personal device

Stop using the suspicious installer and contact your organization’s IT or security team if the device is managed. If it is personal, seek help from a trusted security professional or the software vendor through its verified website. Do not rely on the application opening normally as an all-clear.

In an organization

Security teams should promptly isolate and investigate a suspected device under their incident-response procedures. Microsoft recommends controls including blocking or preventing downloads from untrusted sources and enabling SmartScreen, network protection, tamper protection, and Microsoft Defender XDR. Its report also documents behavior-based hunting queries for randomized paths, security-exclusion tampering, recovery inhibition, scheduled-task execution, and known command-and-control indicators. Because infrastructure and indicators can change, defenders should consult Microsoft’s original report for current hunting details rather than treating an indicator list as evergreen.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How organizations can reduce exposure

  • Provide a managed software catalog or repository and restrict execution of unapproved installers where feasible.
  • Keep endpoint protection and tamper protection enabled; do not rely on signatures or a single product as a guarantee.
  • Monitor for suspicious scheduled tasks, unexpected security-exclusion changes, randomized executable paths, and unusual outbound activity.
  • Investigate suspicious installations promptly and isolate affected devices according to incident-response procedures.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.