Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
ID: 2bee01f2-afa7-5a52-ac0d-087494161ec6
STIX ID: report--2bee01f2-afa7-5a52-ac0d-087494161ec6
Feed Name: The Hacker News
Confiant detailed a malvertising campaign called "SourTrade" that impersonates trading services to fingerprint visitors and dynamically assemble Windows executables in-browser using a legitimate Bun runtime and streamed workers; the attackers supply PE structures and bytecode in /config responses and combine them with ranges from the Bun runtime and generated AES-CTR streams to produce session-unique payloads, complicating hash-based detection. Confiant published three SHA-256 hashes and numerous malicious domains, but the analysis documents delivery up to disk download and does not conclusively attribute or fully characterize the final payload.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
