New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
ID: 2fa7200f-9715-528f-953c-8960b6cd3abf
STIX ID: report--2fa7200f-9715-528f-953c-8960b6cd3abf
Feed Name: The Hacker News
Threat Score
**REF8372 — OXLOADER / CastleStealer:** Researchers disclosed a malvertising campaign that uses malicious Google Ads to redirect users to a fake Node.js site which serves a Storj-hosted batch script that installs a new loader called **OXLOADER**; OXLOADER employs heavy obfuscation, anti-VM checks, DLL sideloading and staging via the Windows.reloc section to deploy the .NET info-stealer **CastleStealer**, showing low detection rates and likely financial motivation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
