Malware · 84 days ago
The trust break is the download itself. A user searching for software and clicking a sponsored result can hand an attacker the first foothold, so a normal reputation check or email-focused phishing playbook misses the lure entirely.
Elastic says OXLOADER is a previously undocumented Windows loader already active in a Google Ads campaign impersonating Node.js. It delivers CASTLESTEALER through a fake download flow and shows low detection across static engines and sandboxes, which is why the loader can look like an ordinary installer path instead of malware.
That makes search ads a practical initial access channel for broad, opportunistic credential theft. The loader’s low visibility means defenders are left watching for abnormal indicators after users do what they already do every day: search the web for software.
2 sources covering this story
New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
Researchers detail REF8372, a malvertising campaign using fake Node.js ads, Storj-hosted payloads, and OXLOADER to deploy CastleStealer.
OXLOADER: new loader evading detection to drop infostealer — Elastic Security Labs
Elastic Security Labs uncovers OXLOADER: a new Windows loader using .reloc section abuse and anti-VM checks to drop infostealer malware via Google Ads.
Part of the PlainSec briefing for 2026-06-22