Cybersecurity researchers at Elastic Security Labs have identified a new malware campaign, codenamed REF8372, that uses malicious Google Ads to distribute the OXLOADER malware and CastleStealer information stealer.
Key Points
- The campaign targets users searching for software like Node.js, redirecting them to fraudulent websites via deceptive Google Ads.
- Threat actors utilize the decentralized cloud storage platform Storj to host malicious payloads and evade domain-based security filters.
- OXLOADER employs advanced obfuscation techniques, including control-flow flattening and mixed Boolean-Arithmetic, to bypass static detection and sandbox analysis.
- The malware performs DLL side-loading to execute the final CastleStealer payload, which is designed to harvest sensitive user information.
- Evidence suggests the attackers are likely Russian-speaking, as the malware includes specific exclusions to avoid infecting systems within the Commonwealth of Independent States.
- Google removed the associated advertiser account and malicious campaigns from its platform on May 14, 2026.