Lost in relocation: analysis of a new loader distributing CASTLESTEALER
Elastic Security Labs discovered OXLOADER, a previously undocumented Windows loader distributing the CASTLESTEALER infostealer via malicious Google Ads impersonating Node.js. The loader employs sophisticated obfuscation (control-flow flattening, mixed Boolean-Arithmetic, opaque predicates), self-modifying decryption stubs, .reloc section abuse for shellcode staging, and five anti-VM/sandbox checks (CPU count, RAM, display refresh rate, network emulation, geographic/language exclusions) to evade detection and analysis. The attack chain uses batch scripts hosted on Storj, UAC bypass, and DonutLoader to deliver .NET-based CASTLESTEALER in-memory, with attribution pointing to Russian-speaking financially motivated threat actors.