Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
ID: c2807734-df5f-59dc-87dd-0e15d38a4533
STIX ID: report--c2807734-df5f-59dc-87dd-0e15d38a4533
Feed Name: CosmicBytez Labs
The report describes the SourTrade malvertising campaign that has victimized 3,000+ Windows users since 2024 by delivering an info-stealer in fragmented chunks across multiple CDNs; a browser-side JavaScript reassembles these chunks (leveraging the legitimately signed Bun runtime) into an executable that is written and run locally, evading static AV and complicating takedowns. Confiant reported the activity and the document includes delivery details, affected sectors, and pragmatic defensive guidance for users and enterprise teams.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
