Hackers Impersonate Node.js Installer in Google Ads to Deploy Infostealer Malware
ID: 97b54bb5-6852-51e4-826a-f74f04c8d7b6
STIX ID: report--97b54bb5-6852-51e4-826a-f74f04c8d7b6
Feed Name: cybersecurityNews.com
Threat Score
Elastic Security Labs reports an active US-targeted malvertising campaign that impersonated the Node.js installer via sponsored Google Ads to deliver OXLOADER, a stealthy loader with multiple sandbox-evasion checks, which in turn loads the CASTLESTEALER infostealer entirely in memory; the report includes technical analysis, IoCs (domains, hashes, C2 IPs), and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
