New OXLOADER Spread via Malicious Google Ads Delivers CastleStealer

Colleagues, please note: cybersecurity teams have identified campaign REF8372 using a new loader, OXLOADER.
Elastic Security Labs reports threat actors abused malicious Google Ads to redirect victims to a fake site and, via Storj, delivered a batch script that launches OXLOADER and subsequently deploys the .NET stealer CastleStealer using DLL side‑loading with UAC escalation.
Key points: obfuscation (CFF, MBA), self‑modifying loaders, anti‑VM measures, and exclusion of CIS PCs — suggesting a financially motivated Russian‑language group.
Why it matters: attackers leverage legitimate services to evade filters and reduce detectability.
How do you validate ads and the reputation of downloaded files?
#cybersecurity #malvertising #infosec #threatintel

