logo

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

ID: bc130bb7-ac9f-5eb9-87fe-24171c121376

STIX ID: report--bc130bb7-ac9f-5eb9-87fe-24171c121376

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

...
...

Elastic Security Labs describes REF8372, a malvertising-driven campaign that lures developers via fraudulent Google Ads to a spoofed site which silently downloads OXLOADER from Storj; OXLOADER uses multilayer obfuscation and anti-analysis techniques to deploy the CastleStealer .NET information stealer. The report provides technical details, IoCs (including domain and SHA-256), and notes overlaps with the GrayBravo cluster and the BackgroundFix campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.