OXLOADER is a newly discovered malware loader that uses control-flow flattening, mixed Boolean-Arithmetic, self-modifying decryption stubs, and abuse of Windows .reloc sections to deliver payloads like CastleStealer. It is distributed via malicious Google Ads and hosted on Storj.