Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
WinSCP

WinSCP Vendor Cyber Rating & Cyber Score

winscp.net

Since 2000, we are developing WinSCP, a popular free file manager for Microsoft Windows, which has been downloaded more than 200 million times! WinSCP is a powerful multi-functional tool that will improve your productivity. WinSCP can copy files between a local and remote computer using multiple protocols: Amazon S3, FTP, FTPS, SCP, SFTP or WebDAV. WinSCP can copy files between two local folders too. On the one hand, WinSCP offers an easy to use graphical user interface; you can choose between Windows Explorer look and tabbed twin-panel interface like Norton commander. On the other hand, advanced users can automate WinSCP functionality using .NET assembly or simple batch file scripting. You can use WinSCP for all common operations with


WinSCP A.I CyberSecurity Scoring

WinSCP
Company Information
Website:http://winscp.net
Employees number:3
Number of followers:1,370
NAICS:5112
Industry Type:Software Development
Homepage:winscp.net
WinSCP Risk Score (AI oriented)
Between 700 and 749
logo
WinSCPSoftware Development
Updated:
10/03/2026
740/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
WinSCP Global Score (TPRM)
xxxx
logo
WinSCPSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

WinSCPModerate
Current Score
740Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
742Before Incident
AUGUST 2026
742Before Incident
JULY 2026
741Before Incident
JUNE 2026
741Before Incident
MAY 2026
741Before Incident
APRIL 2026
741Before Incident
MARCH 2026
740Before Incident
FEBRUARY 2026
740Before Incident
JANUARY 2026
740Before Incident
DECEMBER 2025
739Before Incident
NOVEMBER 2025
739Before Incident
OCTOBER 2025
738Before Incident
JUNE 2024
749Before Incident
Cyber Attack
01 Jun 2024WinSCP
Google and WinSCP: OysterLoader Evasion Tactics Exposed: Advanced Obfuscation and Rhysida Ransomware Ties Uncovered

OysterLoader: A Stealthy Multi-Stage Malware Tied to Rhysida Ransomware

730After Incident
CRITICAL-19
GOOWIN1770971061
OysterLoader: A Stealthy Multi-Stage Malware Tied to Rhysida Ransomware OysterLoader (also known as Broomstick or CleanUp) is a sophisticated C++-based malware loader actively used in campaigns linked to the Rhysida ransomware group. First observed in mid-2024, it spreads through malvertising and SEO-poisoning tactics, disguising itself as trojanized installers for popular IT tools like PuTTY, WinSCP, and Google Authenticator. Once executed, OysterLoader establishes a covert foothold, capable of delivering Rhysida ransomware or commodity info-stealers such as Vidar. Rhysida operators, part of the broader WIZARD SPIDER/Vanilla Tempest cybercrime ecosystem, have heavily invested in this tool, leveraging fraudulent code-signing certificates and malicious ad infrastructure to sustain campaigns despite revocations. While primarily associated with Rhysida, OysterLoader’s payload flexibility suggests it may circulate within a closed criminal network rather than being exclusive to a single group. ### Evasion Tactics & Infection Chain OysterLoader employs a four-stage infection process, beginning with a seemingly legitimate Microsoft Installer (MSI) package often signed to bypass trust checks. Key evasion techniques include: - Stage 1: Acts as a packer/obfuscator, loading the next stage from a shuffled memory blob while flooding execution with superfluous Windows API calls (e.g., GDI functions) to mislead detection. Anti-analysis measures include debugger checks and dynamic API resolution via per-sample hashing. - Stage 2: Uses shellcode with a custom LZMA-like decompression routine, dynamically resolving imports and adjusting memory protections before executing the reconstructed payload. - Stage 3: Functions as a downloader and environment verifier, checking system language and process counts before contacting command-and-control (C2) servers. Earlier variants used HTTPS endpoints with spoofed headers, hiding the next stage in image files via steganography and RC4 encryption. Persistence is achieved via scheduled tasks (e.g., `rundll32` executing `COPYING3.dll` in `%APPDATA%`). - Final Stage: Delivers Rhysida ransomware or other payloads via a DLL-based core, communicating over plain HTTP or domain-based C2 infrastructure. Recent versions use evolving API paths (e.g., `/api/v2/init`, `/api/v2/facade`) and non-standard Base64 encoding with dynamic alphabet shifts to evade detection. ### C2 Infrastructure & Ongoing Threats As of January 2026, active C2 domains include `grandideapay[.]com`, `nucleusgate[.]com`, and `socialcloudguru[.]com`, hosting endpoints like `/api/v2/facade`. The malware’s resilience stems from realistic browser user-agents, multi-server fallback logic, and adaptive encoding schemes, complicating static detection. OysterLoader’s evolution highlights the growing sophistication of loader malware, blending legitimate-looking installers, steganography, and dynamic C2 protocols to evade defenses before deploying ransomware or data-stealing payloads.
INCIDENT DETAILS -
TYPE
Malware Loader
MOTIVATION
Financial gainData exfiltration
IMPACT
Data Compromised: Potential data exfiltration (e.g., personally identifiable information, credentials)Systems Affected: Windows systems with trojanized installers (PuTTY, WinSCP, Google Authenticator)Operational Impact: Potential ransomware deployment leading to system encryption and operational disruptionIdentity Theft Risk: High (if info-stealers like Vidar are deployed)Payment Information Risk: High (if info-stealers like Vidar are deployed)
DATA BREACH
Personally identifiable informationCredentialsPayment informationSensitivity Of Data: HighData Exfiltration: Possible (via Vidar info-stealer or Rhysida ransomware)Data Encryption: Yes (if Rhysida ransomware is deployed)Personally Identifiable Information: Possible

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for WinSCP ?
?
What was WinSCP's A.I Rankiteo Cyber Score in August 2026 ?
?
What was WinSCP's A.I Rankiteo Cyber Score in July 2026 ?
?
What was WinSCP's A.I Rankiteo Cyber Score in June 2026 ?
?
What was WinSCP's A.I Rankiteo Cyber Score in May 2026 ?
?
What was WinSCP's A.I Rankiteo Cyber Score in April 2026 ?
?
What was WinSCP's A.I Rankiteo Cyber Score in March 2026 ?
?
What was WinSCP's A.I Rankiteo Cyber Score in February 2026 ?
?
What was WinSCP's A.I Rankiteo Cyber Score in January 2026 ?
?
What was WinSCP's A.I Rankiteo Cyber Score in December 2025 ?
?
What was WinSCP's A.I Rankiteo Cyber Score in November 2025 ?
?
What was WinSCP's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on WinSCP's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with WinSCP ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view WinSCP's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?