Find notable cyber news and cases, enriched with sources, timelines, and signals.

OXLOADER loader stages CastleStealer via UAC prompting and DLL side-loading

Malware Activity
First reported
Last updated
Happening score
H score 20
1 unique sources, 1 articles

Summary

Hide ▲

The OXLOADER malware activity now shows a loader delivering CastleStealer through PowerShell, UAC prompting, and DLL side-loading, giving the stealer a stealthier path to infected Windows systems. The loader's obfuscation layers and anti-VM checks help it avoid static detection and sandbox analysis. That combination increases the chance that the payload executes before defenders can stop it.

Related Happenings

Veil#Drop PureLog Stealer in-memory delivery operation

Malware Activity
H score30 First: 01.07.2026 17:30 Last: 01.07.2026 17:30 Sources 1

About this happening: Veil#Drop is delivering PureLog Stealer through a fileless chain that keeps payloads entirely in memory, reducing disk artifacts and raising the chance of evading...

TONResolver RAT delivered via ZIP, LNK, and PowerShell

Malware Activity
H score22 First: 30.06.2026 13:30 Last: 30.06.2026 13:30 Sources 1

About this happening: The TONResolver malware implant was delivered through a ZIP/LNK/PowerShell chain that can establish a remote access trojan foothold and enable command execution. T...

SharkLoader loader activity deploying Cobalt Strike Beacon

Malware Activity
H score30 First: 26.06.2026 21:17 Last: 26.06.2026 21:17 Sources 1

About this happening: A newly observed SharkLoader malware operation is staging Cobalt Strike Beacon on compromised Windows hosts, expanding post-compromise control and persistence risk. The lo...

REF8372 malicious Google Ads CastleStealer delivery campaign

Campaign
H score27 First: 22.06.2026 16:20 Last: 22.06.2026 16:20 Sources 1

How related: According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the malware.

About this happening: The REF8372 campaign now uses malicious Google Ads and a fake Node.js download site to deliver OXLOADER and CastleStealer, putting search users at risk of malw...

LeakNet ransomware gang ClickFix and Deno in-memory loader activity

Malware Activity
H score23 First: 17.03.2026 14:09 Last: 17.03.2026 14:09 Sources 1

About this happening: The LeakNet ransomware gang has adopted ClickFix initial access and a Deno-based loader that executes malicious code in memory, making intrusions harder to detect and...

Timeline

  1. 22.06.2026 16:20 1 articles · 23d ago

    Google removes advertiser account tied to malicious ad campaigns

    Mitigation Patch Update

    Google removed the advertiser account and its ad campaigns on May 14, 2026 after the campaign used malicious Google Ads to direct users to the fake node-js[.]prentiva99[.]info site.

    Show sources
  2. 22.06.2026 16:20 2 articles · 23d ago

    Researchers disclose REF8372 campaign delivering OXLOADER and CastleStealer

    Initial Disclosure

    Cybersecurity researchers disclosed REF8372, a campaign that uses malicious Google Ads and a fake node-js[.]prentiva99[.]info site to deliver OXLOADER, a previously unreported loader that downloads a Storj-hosted executable through PowerShell, triggers a Windows User Account Control (UAC) prompt with -Verb RunAs, and uses DLL side-loading to decrypt and execute CastleStealer. The activity is assessed as likely Russian-speaking and financially motivated, with explicit exclusions for machines in the CIS region.

    Show sources