logo

Hackers Abuse Service Workers to Assemble Malware Inside Web Browsers

ID: c42c5d0f-7abd-5c73-ab8e-0b204613bb64

STIX ID: report--c42c5d0f-7abd-5c73-ab8e-0b204613bb64

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2026-07-24

Date Updated: 2026-07-25

Author: Varshini

...
...

SourTrade is an active malvertising campaign (since late 2024) that impersonates trading and crypto services via programmatic ads to lure retail traders into browser-hosted “money pages.” Those pages register ServiceWorkers and SharedWorkers and use a four-stage in-browser assembly pipeline—driven by per-session AES‑CTR seeds and a clean runtime—to construct unique malware executables in memory, defeating hash-based IOCs; campaigns are observed across APAC, LATAM, Africa and selected Western markets, and two SHA256 samples are listed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.