The trust break is the download itself. A user searching for software and clicking a sponsored result can hand an attacker the first foothold, so a normal reputation check or email-focused phishing playbook misses the lure entirely. Elastic says OXLOADER is a previously undocumented Windows loader already active in a Google Ads campaign impersonating Node.js. It delivers CASTLESTEALER through a fake download flow and shows low detection across static engines and sandboxes, which is why the loader can look like an ordinary installer path instead of malware. That makes search ads a practical initial access channel for broad, opportunistic credential theft. The loader’s low visibility means defenders are left watching for abnormal indicators after users do what they already do every day: search the web for software.
Part of the PlainSec briefing for 2026-06-22