๐ต๏ธ RESEARCH & DEEP DIVES
- Malvertising campaign uses JavaScript to assemble malware in browser memory
Malicious sites use JavaScript to build malware directly in browser memory.
- Targets retail traders and crypto investors via fake Solana, Luno, and TradingView sites
- Uses JavaScript with service and shared workers to assemble malware payload locally in browser memory
- Employs randomized config parameters to generate unique malware hashes, evading static detection
- No finished malware file is transmitted over the network, complicating detection and analysis
- Campaign active since late 2024, localized in 25 languages across 12 countries, mainly Asia Pacific and Latin America ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer