Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
JetBrains Patches Critical IntelliJ IDEA RCE and Four TeamCity Flaws
July 24, 2026
Apache Syncope Patches Critical RCE and SQL Injection Vulnerabilities
July 24, 2026
FakeAgent Campaign Uses Malicious Bing Ads and Claude.ai Artifacts to Infect Corporate Users
July 24, 2026
Home/Threats/SourTrade Malvertising Builds Unique Malware in Browsers to Evade Detection
Threats

SourTrade Malvertising Builds Unique Malware in Browsers to Evade Detection

Key Takeaways SourTrade is an ongoing malvertising operation that has been active since late 2024. It targets cryptocurrency users globally by impersonating legitimate trading platforms like...

Marcus Rodriguez
Marcus Rodriguez
July 24, 2026 4 Min Read
2 0

Key Takeaways

  • SourTrade is an ongoing malvertising operation that has been active since late 2024.
  • It targets cryptocurrency users globally by impersonating legitimate trading platforms like TradingView, Solana, and Luno.
  • The campaign uses a sophisticated evasion technique where the victim’s browser assembles the malware locally, rather than downloading a pre-built malicious file.
  • This method makes detection challenging for traditional security tools that rely on file-hash matching.
  • Users should exercise extreme caution with sponsored ads for financial services and always verify URLs directly.

A sophisticated malvertising campaign, dubbed SourTrade, is actively targeting cryptocurrency enthusiasts by leveraging fake advertisements that direct users to convincing replicas of popular trading and exchange platforms. This operation, which began in late 2024, has cast a wide net, impacting users across diverse regions including Asia-Pacific, Latin America, Africa, Australia, and Great Britain.

Table Of Content

  • Key Takeaways
  • SourTrade Malvertising
  • Ads, Cloaking, and Risk
  • What You Should Do

The attackers employ brand impersonation, mimicking well-known services such as TradingView, Solana, and Luno. A key element of their strategy involves rigorous visitor checks designed to deflect security researchers and automated analysis systems. According to Confiant, in a report shared with Cyber Security News (CSN), individuals who do not meet the campaign’s specific targeting criteria are often presented with a benign, blank page, effectively cloaking the malicious intent from unwanted scrutiny.

Researchers at Confiant have uncovered a particularly innovative technique employed by SourTrade: instead of serving a complete malicious executable for download, the campaign orchestrates the assembly of the final malware directly within the victim’s browser. This on-the-fly construction of malware locally within the browser poses significant challenges for conventional security detection mechanisms.

SourTrade Malvertising

The SourTrade attack chain initiates its malicious download process even before a user clicks. Upon landing on a deceptive page, the site registers a ServiceWorker, a browser component capable of intercepting and controlling network requests and downloads. Subsequently, a SharedWorker is activated, which then receives instructions necessary for constructing the final malicious file.

Rather than transmitting a single, identifiable executable, the attackers deliver a collection of disparate components: a template, a clean Bun runtime environment, encrypted data, and unique session-specific values. The victim’s browser then combines these elements in memory, yielding a distinct Windows executable for each individual user or session. This dynamic assembly process severely diminishes the effectiveness of traditional file-hash-based detection methods, as each generated malware instance possesses a unique signature.

This approach significantly complicates forensic investigations, mirroring tactics observed in browser cache malware attacks where browser activity itself becomes integral to the malware delivery. The completed malicious file is ultimately delivered through a same-origin browser download path, managed by the ServiceWorker. For the unsuspecting user, the download appears to originate from the legitimate-looking landing page domain, even though critical parts of the malware’s construction are sourced from separate, attacker-controlled infrastructure.

Ads, Cloaking, and Risk

SourTrade’s operators meticulously craft localized advertisements in English and the respective regional languages to maximize their reach. Their fake platforms are designed to appeal to retail traders, targeting individuals actively seeking charting tools, blockchain project information, or digital asset management services.

Analysts have noted the presence of advertising and tracking logic from several major online advertising ecosystems embedded within the malicious pages. This integration suggests that the attackers are actively measuring traffic and refining their campaigns, a concerning trend also evident in recent Google Ads malware operations that redirect users to deceptive software downloads.

A critical component of the SourTrade campaign is its sophisticated cloaking mechanism. The operation actively fingerprints visitors, presenting a harmless white page to suspected analysts, bots, or any traffic deemed undesirable. Conversely, identified targets are directed to the convincing fake platform, where the malware-building code is deployed.

What You Should Do

  • Exercise Extreme Caution with Ads: Be highly suspicious of sponsored advertisements, particularly those promoting financial tools or cryptocurrency services, especially if they prompt a software download.
  • Verify URLs Directly: Always access financial services and trading platforms by typing their official URLs directly into your browser or using trusted, saved bookmarks. Avoid clicking links from advertisements or suspicious emails.
  • Monitor Browser Activity: Organizations should implement robust monitoring for unusual browser downloads, suspicious advertisement referrals, unexpected ServiceWorker activity, and connections to newly registered or unfamiliar domains. These signals, when analyzed collectively, can indicate a potential compromise.
  • Block Known Indicators: Security teams should proactively block the provided Indicators of Compromise (IoCs) at network perimeters and endpoint protection systems. Any devices that have interacted with these indicators should be thoroughly investigated for compromise.
  • Educate Users: Implement regular cybersecurity awareness training for employees, particularly those involved in financial trading or cryptocurrency, to highlight the dangers of malvertising and phishing tactics.
Type Indicator Description
SHA-256 19a29d26b94b708830c6eaea8a6c17616ec677adaf09114190d0e129564b2ca1b SourTrade malware hash
SHA-256 205c0d056a6b3e76736d4f378541d28f24ecdf40060eeed24d8aa283d2f0120f SourTrade malware hash
SHA-256 63ad542ed44df306bdcbb022ae210da74abad74e978cc1e3992016976282f31976 SourTrade malware hash
Domain noxani[.]info SourTrade domain IOC
Domain greensite[.]digital SourTrade domain IOC
Domain yuntaro[.]digital SourTrade domain IOC
Domain nexlisa[.]info SourTrade domain IOC
Domain vashiro[.]info SourTrade domain IOC
Domain campainter[.]digital SourTrade domain IOC
Domain riovera[.]info SourTrade domain IOC Domain lunavo[.]club SourTrade domain IOC
Domain hanzoa[.]digital SourTrade domain IOC
Domain authcom[.]digital SourTrade domain IOC
Domain fererro[.]digital SourTrade domain IOC
Domain zythera[.]info SourTrade domain IOC
Domain angelxc[.]digital SourTrade domain IOC
Domain toushere[.]digital SourTrade domain IOC
Domain auronix[.]digital SourTrade domain IOC
Domain quorivamesh[.]digital SourTrade domain IOC
Domain junora[.]digital SourTrade domain IOC
Domain savanhe[.]digital SourTrade domain IOC
Domain tenderi[.]digital SourTrade domain IOC
Domain dexarionrte[.]info SourTrade domain IOC
Domain zuvex[.]digital SourTrade domain IOC
Domain minaro[.]club SourTrade domain IOC
Domain praxnova[.]info SourTrade domain IOC
Domain zuvex[.]club SourTrade domain IOC
Domain kalviorix[.]info SourTrade domain IOC
Domain thaivex[.]digital SourTrade domain IOC
Domain form-engine[.]digital SourTrade domain IOC
Domain solventa[.]club SourTrade domain IOC
Domain form-networktool[.]digital SourTrade domain IOC
Domain electmu[.]digital SourTrade domain IOC
Domain zenovapc[.]site SourTrade domain IOC
Domain qumoro[.]site SourTrade domain IOC
Domain insightcores[.]digital SourTrade domain IOC
Domain pulsewave-glow[.]digital SourTrade domain IOC
Domain ignite-spark[.]digital SourTrade domain IOC
Domain riberaz[.]com SourTrade domain IOC
Domain polvexa[.]site SourTrade domain IOC
Domain viewsafc[.]online SourTrade domain IOC
Domain insightmetrix[.]digital SourTrade domain IOC
Domain webnity[.]site SourTrade domain IOC
Domain cirevia1[.]digital SourTrade domain IOC
Domain tvviewreach[.]digital SourTrade domain IOC
Domain alteira[.]digital SourTrade domain IOC
Domain dalasu[.]digital SourTrade domain IOC
Domain parixaxj[.]com SourTrade domain IOC
Domain trustconnect[.]digital SourTrade domain IOC
Domain torvianet[.]site SourTrade domain IOC
Domain nebive[.]site SourTrade domain IOC
Domain forecastlogiccore[.]digital SourTrade domain IOC
Domain netkorava[.]digital SourTrade domain IOC
Domain forecasthub[.]digital SourTrade domain IOC
Domain dotlor[.]site SourTrade domain IOC
Domain koravaje[.]digital SourTrade domain IOC
Domain signalmetrics[.]digital SourTrade domain IOC
Domain forecastbridge[.]digital SourTrade domain IOC
Domain lakorava[.]digital SourTrade domain IOC
Domain pustou[.]site SourTrade domain IOC
Domain insightorbithub[.]digital SourTrade domain IOC
Domain dataroutehub[.]digital SourTrade domain IOC
Domain datasyncengine[.]digital SourTrade domain IOC
Domain forecastdeltaflow[.]digital SourTrade domain IOC
Domain forecastlogicflow[.]digital SourTrade domain IOC
Domain metricforge[.]digital SourTrade domain IOC
Domain forecastpulsegrid[.]digital SourTrade domain IOC
Domain robejj[.]com SourTrade domain IOC
Domain predictcore[.]digital SourTrade domain IOC
Domain dataplanehub[.]site SourTrade domain IOC
Domain oneclickme[.]site SourTrade domain IOC
Domain prolega[.]site SourTrade domain IOC
Domain nameprod[.]site SourTrade domain IOC
Domain transoe[.]site SourTrade domain IOC
Domain orientstrategypartners[.]digital SourTrade domain IOC
Domain beamoramag[.]digital SourTrade domain IOC
Domain beammaybea[.]digital SourTrade domain IOC
Domain urbanleafy[.]info SourTrade domain IOC
Domain brightmosaic[.]info SourTrade domain IOC
Domain forthlira[.]digital SourTrade domain IOC
Domain sobeamora[.]digital SourTrade domain IOC
Domain topbeamora[.]digital SourTrade domain IOC
Domain mortarora[.]digital SourTrade domain IOC
Domain lunarohub[.]info SourTrade domain IOC
Domain worldsol[.]site SourTrade domain IOC
Domain mindflowbase[.]info SourTrade domain IOC
Domain insight-radiant[.]digital SourTrade domain IOC
Domain nordexastudio[.]info SourTrade domain IOC
Domain cognitionpipeline[.]digital SourTrade domain IOC
Domain cognitionnodehub[.]digital SourTrade domain IOC
Domain acuitycore[.]digital SourTrade domain IOC
Domain radiantsynaptic[.]digital SourTrade domain IOC
Domain sapience-flare[.]digital SourTrade domain IOC
Domain engineclaritynode[.]digital SourTrade domain IOC
Domain flare-hub[.]digital SourTrade domain IOC
Domain beacon-net[.]digital SourTrade domain IOC
Domain brainyclevercore[.]digital SourTrade domain IOC
Domain syscodeapi[.]digital SourTrade domain IOC
Domain asiadataintelligencelab[.]digital SourTrade domain IOC

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

ChonkyChicken Malware Steals Chrome Credentials and Spies on Victims

Next Post

Microsoft Confirms No Ads in Windows 11, LG Disables McAfee Pop-ups

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
SourTrade Malvertising Builds Unique Malware in Browsers to Evade Detection
July 24, 2026
ChonkyChicken Malware Steals Chrome Credentials and Spies on Victims
July 24, 2026
Critical Flaws in ChatGPT, Copilot, Gemini Generated Scripts Expose Users
July 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us