New CastleStealer Campaign Uses OXLOADER Loader via Malicious Google Ads
Block malicious Google Ads and monitor for OXLOADER signatures to stop CastleStealer distribution.
Block malicious Google Ads, monitor for OXLOADER signatures, and quarantine affected endpoints.
Summary
Elastic Security Labs has exposed a new malware campaign that delivers CastleStealer via a previously unknown loader called OXLOADER. The attackers use malicious Google Ads as the initial drop point, luring victims into downloading the loader disguised as legitimate content. OXLOADER then installs CastleStealer, a credential‑stealing tool that harvests banking information, passwords, and other sensitive data.
The campaign appears to be run by a financially motivated, Russian‑speaking threat actor, as indicated by language clues and targeting patterns. Researchers found that the loader bypasses standard security controls by leveraging the trust placed in Google Ads. The discovery underscores the need for vigilant ad‑content filtering and endpoint protection against stealthy credential‑stealers.
Key changes
- New malware loader OXLOADER used to deliver CastleStealer
- Campaign leverages malicious Google Ads as initial vector
- Likely Russian-speaking threat actor, financially motivated
- CastleStealer steals credentials, banking info, passwords, etc.
- Loader bypasses standard security controls by leveraging trust in Google Ads
- Campaign active and distributed via Google Ads