HTML page assembling payload in browser and auto-downloading it
A new loader called OXLOADER is being distributed through malicious Google Ads, delivering the CastleStealer infostealer to users searching for legitimate software. HTML smuggling is the mechanism: the page's JavaScript builds the payload as a Blob entirely inside the browser, then triggers a download - so no malicious file ever crosses the network as such, and gateway filters see only a normal-looking web page (MITRE T1027.006). Once the victim opens the downloaded file, the infostealer harvests credentials and browser data. Deep CDR sanitizes the HTML by removing embedded scripts and re-encoding the page, so the browser never assembles the payload in the first place. The demo uses a benign Blob that would only invoke calc, making it safe to run.
Attack Technique
HTML smuggling
MITRE ATT&CK
T1027.006 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗