What's Happening?
The SourTrade malvertising campaign is using a novel method to deliver malware by having victims' browsers assemble the final executable. This operation, active since 2024, targets retail traders and cryptocurrency investors by impersonating legitimate
services like TradingView. The campaign uses a legitimate Bun runtime to build the executable, avoiding detection by traditional security measures. The method involves a complex delivery chain that fingerprints visitors and uses JavaScript to assemble the malware, making it difficult to detect and block.
Why It's Important?
This campaign represents a sophisticated evolution in malvertising tactics, highlighting the increasing complexity of cyber threats. By assembling malware within the browser, attackers can bypass many traditional security defenses, posing a significant challenge for cybersecurity professionals. The campaign's focus on financial and cryptocurrency sectors underscores the high stakes involved, as successful attacks could lead to substantial financial losses. Organizations in these sectors must enhance their security measures to detect and mitigate such advanced threats.











