View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

SourTrade Malvertising Makes Browsers Assemble Malware Executables

๐Ÿ•ต๏ธ RESEARCH & DEEP DIVES

  • SourTrade Malvertising Makes Browsers Assemble Malware Executables in Pieces
    SourTrade malvertising campaign makes browsers build malware executables from pieces.
    • Targets retail traders and cryptocurrency investors via impersonation of TradingView, Solana, and Luno
    • Operates through malvertising landing pages that fingerprint visitors and serve tailored malicious content
    • Uses a legitimate Bun runtime and JavaScript workers to assemble Windows executables in the browser from Base64-encoded pieces
    • No complete malware binary is ever transmitted; each victim receives a unique executable built on the fly
    • Campaign active since late 2024, affecting users across 12 countries in 25 languages
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check