Malicious sites use JavaScript to build malware in browser memory
ID: d4554650-f44c-5ea9-8aac-1f0a20f1b55e
STIX ID: report--d4554650-f44c-5ea9-8aac-1f0a20f1b55e
Feed Name: Bleeping Computer
A malvertising campaign known as "SourTrade" is impersonating Solana, Luno, and TradingView pages and using malicious JavaScript (ServiceWorker/SharedWorker infrastructure) to assemble a unique malware executable in the browser, bypassing delivery of a finished file to evade detection. Active since late 2024 across 12 countries and 25 languages, the operation targets retail traders and crypto investors and employs filtering to avoid researchers; reported payload capabilities include intercepting traffic, stealing cookies/passwords and crypto wallet data, keylogging, screenshots, and persistence, so users are advised to download software only from official sites and verify digital signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
