New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
Incidents: OXLOADER loader delivers CastleStealer via malicious Google Ads, using advanced obfuscation and evasion techniques.
Deep Analysis and Expert Commentary
The attack begins with malicious Google Ads redirecting users to a fake Node.js site, where a batch script hosted on Storj initiates the infection. The script disguises itself as an installer while downloading OXLOADER via PowerShell. The loader employs DLL side-loading to execute CastleStealer, leveraging obfuscation techniques like control-flow flattening and mixed Boolean-Arithmetic to evade detection. The campaign's exclusion of CIS regions suggests a financially motivated, Russian-speaking actor. Defenders should monitor for unusual PowerShell activity, scrutinize Google Ads redirects, and block known IOCs. Storj abuse highlights the need to inspect traffic to legitimate cloud services.
Action Items
- Monitor for unusual PowerShell execution patterns.
- Block known IOCs associated with OXLOADER and CastleStealer.
- Educate users on the risks of clicking on search engine ads.
Original Article Brief Intro
The Hacker News · 2026-06-22 · Incidents: OXLOADER loader delivers CastleStealer via malicious Google Ads, using advanced obfuscation and evasion techniques.
Related Terms and Notes
Malware Families
- CastleStealer — A .NET information stealer distributed via malicious loaders like OXLOADER.
- OXLOADER — A sophisticated malware loader using advanced obfuscation techniques to evade detection.
Context Notes
- Google Ads
- Google Ads Abuse
- Malware
- Malware Campaign