The OXLOADER campaign demonstrates how attackers are abusing search advertisements to direct users toward convincing fake software-download websites.
The attack begins when users search for legitimate software, such as Node.js, and click a malicious Google advertisement. The fake website provides a batch script that displays a fraudulent installation window while secretly using PowerShell to download and execute OXLOADER.
OXLOADER then uses DLL side-loading and several layers of code obfuscation to launch CastleStealer, an information-stealing malware capable of collecting sensitive data from the infected system.
The loader also includes anti-analysis and anti-virtual-machine checks, helping it avoid security sandboxes and maintain a relatively low detection rate.
This campaign shows that sponsored search results should not automatically be treated as trustworthy. Attackers can use verified or compromised advertising accounts and legitimate cloud-storage services to make malicious downloads appear credible.
Organizations should restrict script execution, monitor PowerShell and DLL side-loading activity, and prevent users from installing software obtained through advertisements or unfamiliar websites. Approved software should be downloaded only from verified vendor portals or managed internal repositories.
The key lesson is that a familiar search engine and a professional-looking installer do not guarantee legitimate software. In this campaign, the advertisement was merely the first stage of a carefully disguised malware delivery chain.

Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the malware. Evidence indicates that the threat actor is likely Russian-speaking and financially motivated, owing to the
Source: New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer via The Hacker News — published 22 Jun 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.