VMTech
Discuss a project

New OXLOADER Spread via Malicious Google Ads Delivers CastleStealer

New OXLOADER Spread via Malicious Google Ads Delivers CastleStealer

Colleagues, please note: cybersecurity teams have identified campaign REF8372 using a new loader, OXLOADER.

Elastic Security Labs reports threat actors abused malicious Google Ads to redirect victims to a fake site and, via Storj, delivered a batch script that launches OXLOADER and subsequently deploys the .NET stealer CastleStealer using DLL side‑loading with UAC escalation.

Key points: obfuscation (CFF, MBA), self‑modifying loaders, anti‑VM measures, and exclusion of CIS PCs — suggesting a financially motivated Russian‑language group.

Why it matters: attackers leverage legitimate services to evade filters and reduce detectability.

How do you validate ads and the reputation of downloaded files?

#cybersecurity #malvertising #infosec #threatintel

Open analytics
On the site 1 views
min read 1 28.06.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

New OXLOADER Spread via Malicious Google Ads Delivers CastleStealer

Open the post on Instagram ↗