{"id":1399,"date":"2026-06-22T13:38:05","date_gmt":"2026-06-22T13:38:05","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=1399"},"modified":"2026-06-22T13:38:05","modified_gmt":"2026-06-22T13:38:05","slug":"new-oxloader-loader-uses-malicious-google-ads-to-deliver-castlestealer","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=1399","title":{"rendered":"New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jun 22, 2026<\/span><\/span><span class=\"p-tags\">Malvertising \/ Endpoint Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEi8sz7SHbQd4E8HNEKbvGGSYhPpJrUydP_gCRt_mWYYTr6QHLmChyphenhyphenca6BXhLBXA4OyKw-eS9xbqRqpKcYWFqDp4HoLBYKjVdWzhF0K1pqjX2bPtB91y1P1PZ8gh5r7Bpp-PIeUJVi_Hki91Qf6YjFAtFmf-qh7V9gNzmbEh_A2lISCvCDnNMALAuiqAlkL_\/s1700-e365\/loader.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed <b>OXLOADER<\/b>.<\/p>\n<p>According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the malware. Evidence indicates that the threat actor is likely Russian-speaking and financially motivated, owing to the presence of explicit exclusions to prevent infecting machines located in the Commonwealth of Independent States (CIS) region. The campaign has been codenamed REF8372.<\/p>\n<p>\u00abThe loader uses several obfuscation layers (control-flow flattening, opaque predicates, mixed Boolean-Arithmetic), self-modifying decryption stubs, and abuses the Windows .reloc section to stage shellcode,\u00bb researchers Daniel Stepanic and Jia Yu Chan <a href=\"https:\/\/www.elastic.co\/security-labs\/oxloader-malware-loader-infostealer\">said<\/a> in a technical breakdown.<\/p>\n<p>The attack begins when unsuspecting users enter queries such as \u00ablts version of node.js\u00bb on search engines like Google, redirecting them to a fake website (\u00abnode-js[.]prentiva99[.]info\u00bb) surfaced via bogus ads published under the verified name \u00ab\u0412\u041e\u041b\u041e\u0414\u0418\u041c\u0418\u0420 \u0422\u0415\u0420\u0415\u0429\u0415\u041d\u041a\u041e\u00bb that&#8217;s purportedly based in Ukraine.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-cant-stop-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjPEV6-530TOlxG6PjrmdlY623wpBwduZ7t1HV6flcmO5R4q4AmfixDUzW0CrhlvMVNWbhvOIso-UDNTka4W_W9Chrdj_dglwBZwi7DuePM2IMIl-hfUYVIqBXgfpr_2619K8Gptb4LzwJ6gUbi7lWl2M8AFQJsHEaw63Q7tZ6708YGruiHrr0Y2W9YYxLQ\/s728-e100\/ThreatLocker-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>It&#8217;s currently unknown if the advertiser account is linked to the actual threat actor, or if it&#8217;s a front account or a purchased identity. The advertiser account, along with its ad campaigns, was removed from Google on May 14, 2026.<\/p>\n<p>Users who end up interacting with the site are served a batch script hosted on Storj, a decentralized, open-source cloud storage platform. The abuse of Storj once again illustrates how threat actors continue to leverage legitimate services to evade domain-based reputation filters.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjAVWPTrityiUYPWfWAkZIGqBYY9xdlKUC_bU827p6qZda1IwqdAFR612_AOX2iR-Sc1uhe4KNmUVKn3JFz4v2JOuHPf7ZRiIcQJ-WhW4GVyK1PLXHnRWDqsZgvxiMeppgccfUY2eimyYUOBZXAGwB3e6d8Ns_wbe8Z0cze-Toaq4GtI4OeXKiFtLZTLuUi\/s1700-e365\/elastic.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjAVWPTrityiUYPWfWAkZIGqBYY9xdlKUC_bU827p6qZda1IwqdAFR612_AOX2iR-Sc1uhe4KNmUVKn3JFz4v2JOuHPf7ZRiIcQJ-WhW4GVyK1PLXHnRWDqsZgvxiMeppgccfUY2eimyYUOBZXAGwB3e6d8Ns_wbe8Z0cze-Toaq4GtI4OeXKiFtLZTLuUi\/s1700-e365\/elastic.jpg\" alt=\"\" border=\"0\" data-original-height=\"583\" data-original-width=\"806\"\/><\/a><\/div>\n<p>Running the batch script displays a bogus installation wizard user interface (UI), while stealthily downloading a next-stage payload, a <a href=\"https:\/\/www.virustotal.com\/gui\/file\/9a9939dff297997732aaade9b243d695632cbd64033c5fbcb9de3d09b7e6c28d\/detection\">Storj-hosted executable<\/a> dubbed OXLOADER through a PowerShell command and executing it with -Verb RunAs to trigger a Windows User Account Control (UAC) prompt.\u00a0<\/p>\n<p>The attack then employs DLL side-loading to launch a rogue DLL, which then proceeds to decrypt and execute the CastleStealer payload. OXLOADER also makes use of techniques like control-flow flattening (CFF) and mixed Boolean-Arithmetic (MBA) to evade static detection, while also taking steps to ensure it&#8217;s not run on sandboxed environments.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/vpn-threat-report-m\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhFlTC7RrRZGiFAgASS0noWSL0qsQGFVp8-Hvuw9yp3X3VKRuTcb5SsPX09wJzrdIM6pu1_5lS4EeZp7Sx4iYBpNJkrGnpr08yyaS1HQ5_5TxaCsP6O0OtHNuOkesn6CbNjao1GPulCJk-uljYMSfMZfBYNrngpe669t7jlRn1FqiEnXhsFD1WVkpaYIVgh\/s728-e100\/ai-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>CastleStealer is a .NET information stealer that was recently distributed alongside CastleLoader through a ClickFix-style lure masquerading as a free image-editing tool as part of a campaign codenamed BackgroundFix. CastleLoader is attributed to a threat activity cluster known as GrayBravo.<\/p>\n<p>\u00abOXLOADER is in an early operational phase, but the engineering behind it suggests this family is worth watching,\u00bb Elastic said. \u00abThe code obfuscation, anti-VM measures, benign-looking code used to masquerade its binaries, and unique staging techniques reflect deliberate engineering choices to evade analysis.\u00bb<\/p>\n<p>\u00abThat investment is paying off, resulting in low detection rates across static engines and detonation runs, giving OXLOADER a window to operate before it gets hunted down.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jun 22, 2026Malvertising \/ Endpoint Security Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According&hellip;<\/p>\n","protected":false},"author":1,"featured_media":1400,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[862,2133,529,2,449,33,2132],"class_list":["post-1399","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-ads","tag-castlestealer","tag-deliver","tag-google","tag-loader","tag-malicious","tag-oxloader"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1399","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1399"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/1399\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/1400"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1399"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1399"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1399"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}