AUTO-UPDATED

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

Cybersecurity researchers at Elastic Security Labs have identified a new malware campaign, codenamed REF8372, that uses malicious Google Ads to distribute the OXLOADER malware and CastleStealer information stealer.

Key Points

  • The campaign targets users searching for software like Node.js, redirecting them to fraudulent websites via deceptive Google Ads.
  • Threat actors utilize the decentralized cloud storage platform Storj to host malicious payloads and evade domain-based security filters.
  • OXLOADER employs advanced obfuscation techniques, including control-flow flattening and mixed Boolean-Arithmetic, to bypass static detection and sandbox analysis.
  • The malware performs DLL side-loading to execute the final CastleStealer payload, which is designed to harvest sensitive user information.
  • Evidence suggests the attackers are likely Russian-speaking, as the malware includes specific exclusions to avoid infecting systems within the Commonwealth of Independent States.
  • Google removed the associated advertiser account and malicious campaigns from its platform on May 14, 2026.

Why it Matters

This campaign highlights the growing trend of threat actors leveraging legitimate cloud services and verified ad accounts to bypass traditional security defenses. The sophisticated engineering behind OXLOADER demonstrates a significant investment in evasion tactics, posing a persistent threat to users who rely on search engines to download software.
Internet Published by info@thehackernews.com (The Hacker News)
Read original