As cited
Copy frozen at (site build).
threat intel
Lost in relocation: analysis of a new loader distributing CASTLESTEALER
Elastic Security Labs identified OXLOADER, a previously undocumented Windows loader distributing the CASTLESTEALER infostealer through malicious Google Ads campaigns impersonating Node.js. The loader employs multiple obfuscation techniques including control-flow flattening, self-modifying code, and abuse of the Windows .reloc section to evade detection across static engines and sandboxes. Evidence suggests the threat actor is financially motivated and Russian-speaking, with the campaign targeting US-based users through a fake installation wizard delivered via Storj's legitimate file-sharing service.
Why it matters: US-based users and organizations are exposed to a low-detection loader actively delivering infostealer malware via search ads; practitioners should monitor for OXLOADER signatures and suspicious Node.js download redirects, and consider implementing malvertising defenses and UAC elevation controls.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Lost in relocation: analysis of a new loader distributing CASTLESTEALER
Elastic Security Labs identified OXLOADER, a previously undocumented Windows loader distributing the CASTLESTEALER infostealer through malicious Google Ads campaigns impersonating Node.js. The loader employs multiple obfuscation techniques including control-flow flattening, self-modifying code, and abuse of the Windows .reloc section to evade detection across static engines and sandboxes. Evidence suggests the threat actor is financially motivated and Russian-speaking, with the campaign targeting US-based users through a fake installation wizard delivered via Storj's legitimate file-sharing service.
Why it matters: US-based users and organizations are exposed to a low-detection loader actively delivering infostealer malware via search ads; practitioners should monitor for OXLOADER signatures and suspicious Node.js download redirects, and consider implementing malvertising defenses and UAC elevation controls.
- Source published
- First seen by Cybersecurity Tracker