View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Malvertising campaign builds malware in browser memory via JavaScript

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • Malvertising campaign uses JavaScript to assemble malware in browser memory Malicious sites use JavaScript to build malware directly in browser memory.
    • Targets retail traders and crypto investors via fake Solana, Luno, and TradingView sites
    • Uses JavaScript with service and shared workers to assemble malware payload locally in browser memory
    • Employs randomized config parameters to generate unique malware hashes, evading static detection
    • No finished malware file is transmitted over the network, complicating detection and analysis
    • Campaign active since late 2024, localized in 25 languages across 12 countries, mainly Asia Pacific and Latin America ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via BleepingComputer

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check