Malicious sites use JavaScript to build malware in browser memory

Summary

A malvertising campaign is using deceptive webpages that leverage malicious JavaScript to construct malware within the browser's memory. This technique allows attackers to bypass traditional security measures by avoiding the creation of executable files on disk. The campaign specifically targets users of popular platforms like Solana, Luno, and TradingView.

IFF Assessment

FOE

This article describes a new and sophisticated attack technique that makes it harder for defenders to detect and prevent malware infections, posing a direct threat.

Defender Context

Defenders need to be aware of in-memory malware techniques that bypass traditional file-based detection. Browser security extensions and network monitoring for suspicious script execution can help mitigate these threats. Users should be cautious of unsolicited ads and verify website legitimacy before interacting.

Read Full Story →