Malicious sites use JavaScript to build malware in browser memory
Summary
A malvertising campaign is using deceptive webpages that leverage malicious JavaScript to construct malware within the browser's memory. This technique allows attackers to bypass traditional security measures by avoiding the creation of executable files on disk. The campaign specifically targets users of popular platforms like Solana, Luno, and TradingView.
IFF Assessment
This article describes a new and sophisticated attack technique that makes it harder for defenders to detect and prevent malware infections, posing a direct threat.
Defender Context
Defenders need to be aware of in-memory malware techniques that bypass traditional file-based detection. Browser security extensions and network monitoring for suspicious script execution can help mitigate these threats. Users should be cautious of unsolicited ads and verify website legitimacy before interacting.