Hackers Abuse Service Workers to Assemble Malware Inside Web Browsers
ID: c42c5d0f-7abd-5c73-ab8e-0b204613bb64
STIX ID: report--c42c5d0f-7abd-5c73-ab8e-0b204613bb64
Feed Name: Cyber Press
SourTrade is an active malvertising campaign (since late 2024) that impersonates trading and crypto services via programmatic ads to lure retail traders into browser-hosted “money pages.” Those pages register ServiceWorkers and SharedWorkers and use a four-stage in-browser assembly pipeline—driven by per-session AES‑CTR seeds and a clean runtime—to construct unique malware executables in memory, defeating hash-based IOCs; campaigns are observed across APAC, LATAM, Africa and selected Western markets, and two SHA256 samples are listed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
