WinSCP A.I CyberSecurity Scoring
WinSCP
Company Information
Website:http://winscp.net
Employees number:3
Number of followers:1,370
NAICS:5112
Industry Type:Software Development
Homepage:winscp.net
WinSCP Risk Score (AI oriented)
Between 700 and 749
WinSCPSoftware Development
Updated:
10/03/2026
10/03/2026
740/1000
Moderate
Ba
WinSCP Global Score (TPRM)
xxxx
WinSCPSoftware Development
Score locked

WinSCPModerate
Current Score
740Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
742
AUGUST 2026
742
JULY 2026
741
JUNE 2026
741
MAY 2026
741
APRIL 2026
741
MARCH 2026
740
FEBRUARY 2026
740
JANUARY 2026
740
DECEMBER 2025
739
NOVEMBER 2025
739
OCTOBER 2025
738
JUNE 2024
749
Cyber Attack
01 Jun 2024 • WinSCP
Google and WinSCP: OysterLoader Evasion Tactics Exposed: Advanced Obfuscation and Rhysida Ransomware Ties Uncovered
OysterLoader: A Stealthy Multi-Stage Malware Tied to Rhysida Ransomware
730
CRITICAL-19
GOOWIN1770971061
OysterLoader: A Stealthy Multi-Stage Malware Tied to Rhysida Ransomware
OysterLoader (also known as Broomstick or CleanUp) is a sophisticated C++-based malware loader actively used in campaigns linked to the Rhysida ransomware group. First observed in mid-2024, it spreads through malvertising and SEO-poisoning tactics, disguising itself as trojanized installers for popular IT tools like PuTTY, WinSCP, and Google Authenticator.
Once executed, OysterLoader establishes a covert foothold, capable of delivering Rhysida ransomware or commodity info-stealers such as Vidar. Rhysida operators, part of the broader WIZARD SPIDER/Vanilla Tempest cybercrime ecosystem, have heavily invested in this tool, leveraging fraudulent code-signing certificates and malicious ad infrastructure to sustain campaigns despite revocations.
While primarily associated with Rhysida, OysterLoader’s payload flexibility suggests it may circulate within a closed criminal network rather than being exclusive to a single group.
### Evasion Tactics & Infection Chain
OysterLoader employs a four-stage infection process, beginning with a seemingly legitimate Microsoft Installer (MSI) package often signed to bypass trust checks. Key evasion techniques include:
- Stage 1: Acts as a packer/obfuscator, loading the next stage from a shuffled memory blob while flooding execution with superfluous Windows API calls (e.g., GDI functions) to mislead detection. Anti-analysis measures include debugger checks and dynamic API resolution via per-sample hashing.
- Stage 2: Uses shellcode with a custom LZMA-like decompression routine, dynamically resolving imports and adjusting memory protections before executing the reconstructed payload.
- Stage 3: Functions as a downloader and environment verifier, checking system language and process counts before contacting command-and-control (C2) servers. Earlier variants used HTTPS endpoints with spoofed headers, hiding the next stage in image files via steganography and RC4 encryption. Persistence is achieved via scheduled tasks (e.g., `rundll32` executing `COPYING3.dll` in `%APPDATA%`).
- Final Stage: Delivers Rhysida ransomware or other payloads via a DLL-based core, communicating over plain HTTP or domain-based C2 infrastructure. Recent versions use evolving API paths (e.g., `/api/v2/init`, `/api/v2/facade`) and non-standard Base64 encoding with dynamic alphabet shifts to evade detection.
### C2 Infrastructure & Ongoing Threats
As of January 2026, active C2 domains include `grandideapay[.]com`, `nucleusgate[.]com`, and `socialcloudguru[.]com`, hosting endpoints like `/api/v2/facade`. The malware’s resilience stems from realistic browser user-agents, multi-server fallback logic, and adaptive encoding schemes, complicating static detection.
OysterLoader’s evolution highlights the growing sophistication of loader malware, blending legitimate-looking installers, steganography, and dynamic C2 protocols to evade defenses before deploying ransomware or data-stealing payloads.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for WinSCP ??
What was WinSCP's A.I Rankiteo Cyber Score in August 2026 ??
What was WinSCP's A.I Rankiteo Cyber Score in July 2026 ??
What was WinSCP's A.I Rankiteo Cyber Score in June 2026 ??
What was WinSCP's A.I Rankiteo Cyber Score in May 2026 ??
What was WinSCP's A.I Rankiteo Cyber Score in April 2026 ??
What was WinSCP's A.I Rankiteo Cyber Score in March 2026 ??
What was WinSCP's A.I Rankiteo Cyber Score in February 2026 ??
What was WinSCP's A.I Rankiteo Cyber Score in January 2026 ??
What was WinSCP's A.I Rankiteo Cyber Score in December 2025 ??
What was WinSCP's A.I Rankiteo Cyber Score in November 2025 ??
What was WinSCP's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on WinSCP's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with WinSCP ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view WinSCP's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?