Thehackernews OXLOADER Malware Loader Delivers CASTLESTEALER via Malicious Google Ads
Article Content
- •OXLOADER uses advanced obfuscation and evasion techniques to deliver CASTLESTEALER.
- •The malware is distributed through malicious Google Ads impersonating legitimate software.
- •Victims are primarily targeted in the CIS region by a Russian-speaking threat actor.
A new Windows loader named OXLOADER is delivering the CASTLESTEALER infostealer through malicious Google Ads. This previously undocumented malware employs advanced obfuscation techniques and abuses the Windows .reloc section to evade detection. Victims searching for Node.js were redirected to a fake landing page, leading to a batch script hosted on Storj that executed OXLOADER. The threat actor is believed to be a financially motivated Russian-speaking group, with the campaign targeting users in the CIS region. The malicious ads were removed from Google on May 14, 2026, but the threat remains active. The loader uses multiple anti-VM checks and sophisticated code-hiding techniques to avoid detection by security tools.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track RAlord, CastleStealer and Eriell Group in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…