OXLOADER loader stages CastleStealer via UAC prompting and DLL side-loading
Malware Activity
Summary
Hide ▲
Show ▼
The OXLOADER malware activity now shows a loader delivering CastleStealer through PowerShell, UAC prompting, and DLL side-loading, giving the stealer a stealthier path to infected Windows systems. The loader's obfuscation layers and anti-VM checks help it avoid static detection and sandbox analysis. That combination increases the chance that the payload executes before defenders can stop it.
Related Happenings
Veil#Drop PureLog Stealer in-memory delivery operation
Malware Activity
H score30
First: 01.07.2026 17:30
Last: 01.07.2026 17:30
Sources 1
About this happening:
Veil#Drop is delivering PureLog Stealer through a fileless chain that keeps payloads entirely in memory, reducing disk artifacts and raising the chance of evading...
Veil#Drop PureLog Stealer in-memory delivery operation
Malware ActivityAbout this happening: Veil#Drop is delivering PureLog Stealer through a fileless chain that keeps payloads entirely in memory, reducing disk artifacts and raising the chance of evading...
TONResolver RAT delivered via ZIP, LNK, and PowerShell
Malware Activity
H score22
First: 30.06.2026 13:30
Last: 30.06.2026 13:30
Sources 1
About this happening:
The TONResolver malware implant was delivered through a ZIP/LNK/PowerShell chain that can establish a remote access trojan foothold and enable command execution. T...
TONResolver RAT delivered via ZIP, LNK, and PowerShell
Malware ActivityAbout this happening: The TONResolver malware implant was delivered through a ZIP/LNK/PowerShell chain that can establish a remote access trojan foothold and enable command execution. T...
SharkLoader loader activity deploying Cobalt Strike Beacon
Malware Activity
H score30
First: 26.06.2026 21:17
Last: 26.06.2026 21:17
Sources 1
About this happening:
A newly observed SharkLoader malware operation is staging Cobalt Strike Beacon on compromised Windows hosts, expanding post-compromise control and persistence risk. The lo...
SharkLoader loader activity deploying Cobalt Strike Beacon
Malware ActivityAbout this happening: A newly observed SharkLoader malware operation is staging Cobalt Strike Beacon on compromised Windows hosts, expanding post-compromise control and persistence risk. The lo...
REF8372 malicious Google Ads CastleStealer delivery campaign
Campaign
H score27
First: 22.06.2026 16:20
Last: 22.06.2026 16:20
Sources 1
How related:
According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the malware.
About this happening:
The REF8372 campaign now uses malicious Google Ads and a fake Node.js download site to deliver OXLOADER and CastleStealer, putting search users at risk of malw...
REF8372 malicious Google Ads CastleStealer delivery campaign
CampaignHow related: According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute the malware.
About this happening: The REF8372 campaign now uses malicious Google Ads and a fake Node.js download site to deliver OXLOADER and CastleStealer, putting search users at risk of malw...
LeakNet ransomware gang ClickFix and Deno in-memory loader activity
Malware Activity
H score23
First: 17.03.2026 14:09
Last: 17.03.2026 14:09
Sources 1
About this happening:
The LeakNet ransomware gang has adopted ClickFix initial access and a Deno-based loader that executes malicious code in memory, making intrusions harder to detect and...
LeakNet ransomware gang ClickFix and Deno in-memory loader activity
Malware ActivityAbout this happening: The LeakNet ransomware gang has adopted ClickFix initial access and a Deno-based loader that executes malicious code in memory, making intrusions harder to detect and...
Timeline
-
22.06.2026 16:20 1 articles · 23d ago
Google removes advertiser account tied to malicious ad campaigns
Mitigation Patch UpdateGoogle removed the advertiser account and its ad campaigns on May 14, 2026 after the campaign used malicious Google Ads to direct users to the fake node-js[.]prentiva99[.]info site.
Show sources
- New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer — thehackernews.com — 22.06.2026 16:20
-
22.06.2026 16:20 2 articles · 23d ago
Researchers disclose REF8372 campaign delivering OXLOADER and CastleStealer
Initial DisclosureCybersecurity researchers disclosed REF8372, a campaign that uses malicious Google Ads and a fake node-js[.]prentiva99[.]info site to deliver OXLOADER, a previously unreported loader that downloads a Storj-hosted executable through PowerShell, triggers a Windows User Account Control (UAC) prompt with -Verb RunAs, and uses DLL side-loading to decrypt and execute CastleStealer. The activity is assessed as likely Russian-speaking and financially motivated, with explicit exclusions for machines in the CIS region.
Show sources
- New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer — thehackernews.com — 22.06.2026 16:20
- New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer — thehackernews.com — 22.06.2026 16:20