SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design
ID: 0bbddbe1-ef0c-50a8-a0d4-98a90d953231
STIX ID: report--0bbddbe1-ef0c-50a8-a0d4-98a90d953231
Feed Name: GBHackers
SourTrade is an active, high‑sophistication malvertising campaign (since late 2024) that abuses programmatic ads and cloaked landing pages to fingerprint victims and instruct browsers to assemble unique Windows executables in-memory using a fetched Bun runtime, C2 blobs, and AES‑CTR-generated bytes, ensuring per-victim hashes and evasion of traditional detection; the chain culminates in ServiceWorker-mediated delivery and MotW manipulation to appear same-origin, and has been used to deliver info-stealer payloads across multiple platforms and geographies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
