<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Oxloader on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/oxloader/</link><description>Recent content in Oxloader on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Sun, 22 Jun 2025 13:20:12 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/oxloader/index.xml" rel="self" type="application/rss+xml"/><item><title>OXLOADER Malware Uses Google Ads to Drop CastleStealer</title><link>https://zxcloudsecurity.co.uk/posts/oxloader-malvertising-google-ads-castlestealer-infostealer/</link><pubDate>Mon, 22 Jun 2026 13:20:12 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/oxloader-malvertising-google-ads-castlestealer-infostealer/</guid><description>Elastic Security Labs exposes OXLOADER, a new malware loader using malicious Google Ads to deliver the CastleStealer infostealer. Learn what security teams</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html">The Hacker News</a></p>
<hr>
<p>A newly identified malware loader called OXLOADER is being distributed via malicious Google Ads, ultimately delivering an information-stealing payload known as CastleStealer. The campaign is attributed to a likely Russian-speaking, financially motivated threat actor. This matters because malvertising via Google Ads is a highly effective initial access vector that bypasses traditional perimeter defences by exploiting trusted ad infrastructure.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review and enforce DNS filtering and web proxy policies to block known malvertising domains, and consider deploying endpoint detection rules for OXLOADER behavioural indicators published by Elastic Security Labs. Ensure browser isolation or ad-blocking controls are in place for corporate endpoints, particularly for users with access to sensitive cloud credentials.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/new-oxloader-loader-uses-malicious.html">New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer</a></p>
]]></content:encoded></item></channel></rss>