New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
ID: bc130bb7-ac9f-5eb9-87fe-24171c121376
STIX ID: report--bc130bb7-ac9f-5eb9-87fe-24171c121376
Feed Name: CosmicBytez Labs
Threat Score
Elastic Security Labs describes REF8372, a malvertising-driven campaign that lures developers via fraudulent Google Ads to a spoofed site which silently downloads OXLOADER from Storj; OXLOADER uses multilayer obfuscation and anti-analysis techniques to deploy the CastleStealer .NET information stealer. The report provides technical details, IoCs (including domain and SHA-256), and notes overlaps with the GrayBravo cluster and the BackgroundFix campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
