Malvertising Campaign SourTrade Uses Browsers to Spread Malware
A new malvertising campaign named SourTrade has emerged as a serious threat to internet users. This operation, active since late 2024, compels the victims' browsers to create the final Windows executable themselves. Instead of delivering a complete malicious file from a fixed URL, SourTrade uses a legitimate Bun runtime environment as its foundation. The security firm Confiant published details about this campaign on July 23, 2026.
According to researchers, SourTrade specifically targets retailers active in the areas of TradingView, Solana, and Luno. These platforms are mimicked by the attackers to gain users' trust and entice them into downloading the malware. The technique employed by SourTrade is particularly sophisticated. Instead of directly transferring the malware, the victim's browser is made to generate the necessary components itself. This is achieved by loading scripts capable of transmitting the malware in small parts and then assembling it into an executable program within the browser.
The use of legitimate software components to create malware is a growing trend in cybercrime. This method complicates detection by security software, as the malware is not present in its complete form when transmitted over the internet. The attackers leverage this technique to increase the likelihood that their malicious activities remain undetected. The campaign has already found numerous victims, particularly among users of trading platforms. The attackers utilize targeted advertising to reach their audience.
This advertising often appears in the form of banners or pop-ups that seem to originate from legitimate platforms. Confiant's security researchers have noted that the campaign unfolds in several phases. Initially, the user is attracted by an engaging advertisement. After clicking on the ad, the user is redirected to a fake website that imitates the legitimate platform. There, the user is prompted to download a file that actually contains the malware.
The malware itself is designed to run in the background and take control of the victim's system. Once installed, it can steal data, intercept passwords, and even load additional malware. The attackers have the ability to continuously update the malware to bypass security measures. The discovery of this campaign has reignited the discussion about the security of online trading platforms. Experts warn that users should exercise caution when clicking on links in advertisements, especially those from lesser-known platforms.
Using security software is strongly recommended to protect against such threats. The security firm Confiant has already taken steps to halt the spread of SourTrade. They are working closely with the affected platforms to inform users about the threat and warn them. Researchers emphasize that educating users about such threats is crucial to reducing the effectiveness of these attacks. The SourTrade campaign is an example of the ever-evolving tactics of cybercriminals.
The use of malvertising and the ability to create malware within the victim's browser pose a serious challenge to cybersecurity. The security community must continue to develop innovative solutions to counter such threats. The vulnerability exploited by SourTrade affects a wide range of users worldwide. Confiant estimates that the campaign has reached several million users since its inception, underscoring the urgency of implementing security measures.
💬 Comentarii (0)
Inca nu exista comentarii. Fii primul!