hacker-news · Crawled Jul 25, 2026
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
2 IoCs 1 Malware
Read original article ↗
AI Summary
A malvertising campaign dubbed SourTrade has been active since late 2024, targeting retail traders and cryptocurrency investors across 12 countries by impersonating legitimate services like TradingView, Solana, and Luno. The attack uses a legitimate Bun runtime to dynamically assemble Windows executables within the victim's browser, leveraging ServiceWorker and SharedWorker to build malware pieces in memory. This technique avoids delivering a complete malicious binary over the network, instead using Base64-encoded components and AES-CTR-generated streams to create unique per-session payloads, evading hash-based detection.
AI-extracted · verify before operational use
Extracted Entities 1 found
Indicators of Compromise 2 extracted
MITRE ATT&CK TTPs 12 techniques
T1003 OS Credential Dumping · Credential Access T1003.001 LSASS Memory · Credential Access T1005 Data from Local System · Collection T1059.001 PowerShell · Execution T1059.007 JavaScript · Execution T1070.004 File Deletion · Defense Evasion T1071.001 Web Protocols · Command And Control T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1204.002 Malicious File · Execution T1555 Credentials from Password Stores · Credential Access T1555.003 Credentials from Web Browsers · Credential Access