Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

Summary

A malvertising operation named SourTrade has been discovered that uses victim browsers to construct the final Windows executable. This campaign impersonates legitimate financial trading platforms like TradingView, Solana, and Luno to target retail traders.

IFF Assessment

FOE

This campaign represents a sophisticated attack vector that bypasses traditional detection methods by having the victim's browser assemble the malware, making it harder for defenders to identify and block malicious payloads.

Defender Context

Defenders should be aware of evolving malvertising techniques that leverage client-side execution for malware delivery. This trend necessitates robust endpoint detection and response (EDR) capabilities that can monitor for suspicious process creation and dynamic code execution within the browser environment.

Read Full Story →