New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
- Posted on June 22, 2026
- By The Hacker News
- 0 Views
- 1 min read
New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer
Researchers detail REF8372, a malvertising campaign using fake Node.js ads, Storj-hosted payloads, and OXLOADER to deploy CastleStealer.