๐ต๏ธ RESEARCH & DEEP DIVES
- SourTrade Malvertising Makes Browsers Assemble Malware Executables in Pieces
SourTrade malvertising campaign makes browsers build malware executables from pieces.- Targets retail traders and cryptocurrency investors via impersonation of TradingView, Solana, and Luno
- Operates through malvertising landing pages that fingerprint visitors and serve tailored malicious content
- Uses a legitimate Bun runtime and JavaScript workers to assemble Windows executables in the browser from Base64-encoded pieces
- No complete malware binary is ever transmitted; each victim receives a unique executable built on the fly
- Campaign active since late 2024, affecting users across 12 countries in 25 languages
๐ Coverage: thehackernews.com ยท ๐ via The Hacker News