logo

SourTrade Malvertising Campaign Secretly Builds Malware in the Browser

ID: fcd303cf-5ab0-59ef-b836-1dece6d1f035

STIX ID: report--fcd303cf-5ab0-59ef-b836-1dece6d1f035

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

...
...

Confiant researchers detail SourTrade, a malvertising campaign active since 2024 that impersonates trading and crypto sites (e.g., TradingView, Solana, Luno) to lure victims and then uses JavaScript-delivered assembly instructions to fetch benign-seeming components and build an infostealer entirely in the browser memory, avoiding distribution of a complete malware binary on the network and evading file-fingerprinting defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.