Lost in relocation: analysis of a new loader distributing CASTLESTEALER (opens in new tab)
Find out how a new obfuscated loader evades static detection using .reloc section abuse, five anti-VM/language checks and MBA obfuscation to deliver infostealer malware via Google Ads.
Read the original article