malware New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer A new malware loader, dubbed OXLOADER, is being used to distribute the CastleStealer information stealer through malicious Google Ads. The campaign, codenamed REF8372, leverages deceptive advertising and PowerShell execution to deliver the payload, employing sophisticated obfuscation techniques to evade detection. This… The Hacker News · Jun 22, 2026 Medium RUUAgoogle adsmalware loadercastlestealer