logo

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

ID: 2fa7200f-9715-528f-953c-8960b6cd3abf

STIX ID: report--2fa7200f-9715-528f-953c-8960b6cd3abf

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: [email protected] (The Hacker News)

...
...

**REF8372 — OXLOADER / CastleStealer:** Researchers disclosed a malvertising campaign that uses malicious Google Ads to redirect users to a fake Node.js site which serves a Storj-hosted batch script that installs a new loader called **OXLOADER**; OXLOADER employs heavy obfuscation, anti-VM checks, DLL sideloading and staging via the Windows.reloc section to deploy the .NET info-stealer **CastleStealer**, showing low detection rates and likely financial motivation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.