New OXLOADER Malware Uses Google Ads to Deliver CastleStealer Infostealer

New OXLOADER Malware Uses Google Ads to Deliver CastleStealer Infostealer

3h ago GbhackersThehackernews 76% similarity 64.5
Share:

Article Content

Browse articles
ThreatCluster

A new Windows loader named OXLOADER has been identified, utilizing advanced obfuscation techniques to evade detection. This malware delivers the CASTLESTEALER infostealer through malicious Google Ads that impersonate legitimate software like Node.js and API Monitor. Victims are redirected through intermediary domains to download and execute OXLOADER via Storj-hosted batch scripts. The campaign highlights the increasing sophistication of malware delivery methods, particularly through malvertising. As of now, there are no reported numbers of affected users or organizations. Security professionals are advised to remain vigilant against such threats. The current status of the malware is active and ongoing.

Key Points: • OXLOADER employs advanced obfuscation to evade detection and analysis. • The malware is delivered via malicious Google Ads impersonating legitimate software. • CASTLESTEALER infostealer is the primary payload of the OXLOADER malware.

ThreatCluster AI

Timeline

2026-06-22
OXLOADER identified
A previously undocumented Windows loader was discovered, utilizing sophisticated obfuscation techniques.
Gbhackers
2026-06-22
Malicious Google Ads campaign launched
The campaign uses Google Ads to impersonate Node.js and API Monitor, redirecting victims to download OXLOADER.
Thehackernews

Community

Browse all →