SourTrade Malvertising Builds Unique Malware in Browsers to Evade Detection
Key Takeaways SourTrade is an ongoing malvertising operation that has been active since late 2024. It targets cryptocurrency users globally by impersonating legitimate trading platforms like...
Key Takeaways
- SourTrade is an ongoing malvertising operation that has been active since late 2024.
- It targets cryptocurrency users globally by impersonating legitimate trading platforms like TradingView, Solana, and Luno.
- The campaign uses a sophisticated evasion technique where the victim’s browser assembles the malware locally, rather than downloading a pre-built malicious file.
- This method makes detection challenging for traditional security tools that rely on file-hash matching.
- Users should exercise extreme caution with sponsored ads for financial services and always verify URLs directly.
A sophisticated malvertising campaign, dubbed SourTrade, is actively targeting cryptocurrency enthusiasts by leveraging fake advertisements that direct users to convincing replicas of popular trading and exchange platforms. This operation, which began in late 2024, has cast a wide net, impacting users across diverse regions including Asia-Pacific, Latin America, Africa, Australia, and Great Britain.
Table Of Content
The attackers employ brand impersonation, mimicking well-known services such as TradingView, Solana, and Luno. A key element of their strategy involves rigorous visitor checks designed to deflect security researchers and automated analysis systems. According to Confiant, in a report shared with Cyber Security News (CSN), individuals who do not meet the campaign’s specific targeting criteria are often presented with a benign, blank page, effectively cloaking the malicious intent from unwanted scrutiny.
Researchers at Confiant have uncovered a particularly innovative technique employed by SourTrade: instead of serving a complete malicious executable for download, the campaign orchestrates the assembly of the final malware directly within the victim’s browser. This on-the-fly construction of malware locally within the browser poses significant challenges for conventional security detection mechanisms.
SourTrade Malvertising
The SourTrade attack chain initiates its malicious download process even before a user clicks. Upon landing on a deceptive page, the site registers a ServiceWorker, a browser component capable of intercepting and controlling network requests and downloads. Subsequently, a SharedWorker is activated, which then receives instructions necessary for constructing the final malicious file.
Rather than transmitting a single, identifiable executable, the attackers deliver a collection of disparate components: a template, a clean Bun runtime environment, encrypted data, and unique session-specific values. The victim’s browser then combines these elements in memory, yielding a distinct Windows executable for each individual user or session. This dynamic assembly process severely diminishes the effectiveness of traditional file-hash-based detection methods, as each generated malware instance possesses a unique signature.
This approach significantly complicates forensic investigations, mirroring tactics observed in browser cache malware attacks where browser activity itself becomes integral to the malware delivery. The completed malicious file is ultimately delivered through a same-origin browser download path, managed by the ServiceWorker. For the unsuspecting user, the download appears to originate from the legitimate-looking landing page domain, even though critical parts of the malware’s construction are sourced from separate, attacker-controlled infrastructure.
Ads, Cloaking, and Risk
SourTrade’s operators meticulously craft localized advertisements in English and the respective regional languages to maximize their reach. Their fake platforms are designed to appeal to retail traders, targeting individuals actively seeking charting tools, blockchain project information, or digital asset management services.
Analysts have noted the presence of advertising and tracking logic from several major online advertising ecosystems embedded within the malicious pages. This integration suggests that the attackers are actively measuring traffic and refining their campaigns, a concerning trend also evident in recent Google Ads malware operations that redirect users to deceptive software downloads.
A critical component of the SourTrade campaign is its sophisticated cloaking mechanism. The operation actively fingerprints visitors, presenting a harmless white page to suspected analysts, bots, or any traffic deemed undesirable. Conversely, identified targets are directed to the convincing fake platform, where the malware-building code is deployed.
What You Should Do
- Exercise Extreme Caution with Ads: Be highly suspicious of sponsored advertisements, particularly those promoting financial tools or cryptocurrency services, especially if they prompt a software download.
- Verify URLs Directly: Always access financial services and trading platforms by typing their official URLs directly into your browser or using trusted, saved bookmarks. Avoid clicking links from advertisements or suspicious emails.
- Monitor Browser Activity: Organizations should implement robust monitoring for unusual browser downloads, suspicious advertisement referrals, unexpected ServiceWorker activity, and connections to newly registered or unfamiliar domains. These signals, when analyzed collectively, can indicate a potential compromise.
- Block Known Indicators: Security teams should proactively block the provided Indicators of Compromise (IoCs) at network perimeters and endpoint protection systems. Any devices that have interacted with these indicators should be thoroughly investigated for compromise.
- Educate Users: Implement regular cybersecurity awareness training for employees, particularly those involved in financial trading or cryptocurrency, to highlight the dangers of malvertising and phishing tactics.
| Type | Indicator | Description | |||
|---|---|---|---|---|---|
| SHA-256 | 19a29d26b94b708830c6eaea8a6c17616ec677adaf09114190d0e129564b2ca1b |
SourTrade malware hash | |||
| SHA-256 | 205c0d056a6b3e76736d4f378541d28f24ecdf40060eeed24d8aa283d2f0120f |
SourTrade malware hash | |||
| SHA-256 | 63ad542ed44df306bdcbb022ae210da74abad74e978cc1e3992016976282f31976 |
SourTrade malware hash | |||
| Domain | noxani[.]info |
SourTrade domain IOC | |||
| Domain | greensite[.]digital |
SourTrade domain IOC | |||
| Domain | yuntaro[.]digital |
SourTrade domain IOC | |||
| Domain | nexlisa[.]info |
SourTrade domain IOC | |||
| Domain | vashiro[.]info |
SourTrade domain IOC | |||
| Domain | campainter[.]digital |
SourTrade domain IOC | |||
| Domain | riovera[.]info |
SourTrade domain IOC | Domain | lunavo[.]club |
SourTrade domain IOC |
| Domain | hanzoa[.]digital |
SourTrade domain IOC | |||
| Domain | authcom[.]digital |
SourTrade domain IOC | |||
| Domain | fererro[.]digital |
SourTrade domain IOC | |||
| Domain | zythera[.]info |
SourTrade domain IOC | |||
| Domain | angelxc[.]digital |
SourTrade domain IOC | |||
| Domain | toushere[.]digital |
SourTrade domain IOC | |||
| Domain | auronix[.]digital |
SourTrade domain IOC | |||
| Domain | quorivamesh[.]digital |
SourTrade domain IOC | |||
| Domain | junora[.]digital |
SourTrade domain IOC | |||
| Domain | savanhe[.]digital |
SourTrade domain IOC | |||
| Domain | tenderi[.]digital |
SourTrade domain IOC | |||
| Domain | dexarionrte[.]info |
SourTrade domain IOC | |||
| Domain | zuvex[.]digital |
SourTrade domain IOC | |||
| Domain | minaro[.]club |
SourTrade domain IOC | |||
| Domain | praxnova[.]info |
SourTrade domain IOC | |||
| Domain | zuvex[.]club |
SourTrade domain IOC | |||
| Domain | kalviorix[.]info |
SourTrade domain IOC | |||
| Domain | thaivex[.]digital |
SourTrade domain IOC | |||
| Domain | form-engine[.]digital |
SourTrade domain IOC | |||
| Domain | solventa[.]club |
SourTrade domain IOC | |||
| Domain | form-networktool[.]digital |
SourTrade domain IOC | |||
| Domain | electmu[.]digital |
SourTrade domain IOC | |||
| Domain | zenovapc[.]site |
SourTrade domain IOC | |||
| Domain | qumoro[.]site |
SourTrade domain IOC | |||
| Domain | insightcores[.]digital |
SourTrade domain IOC | |||
| Domain | pulsewave-glow[.]digital |
SourTrade domain IOC | |||
| Domain | ignite-spark[.]digital |
SourTrade domain IOC | |||
| Domain | riberaz[.]com |
SourTrade domain IOC | |||
| Domain | polvexa[.]site |
SourTrade domain IOC | |||
| Domain | viewsafc[.]online |
SourTrade domain IOC | |||
| Domain | insightmetrix[.]digital |
SourTrade domain IOC | |||
| Domain | webnity[.]site |
SourTrade domain IOC | |||
| Domain | cirevia1[.]digital |
SourTrade domain IOC | |||
| Domain | tvviewreach[.]digital |
SourTrade domain IOC | |||
| Domain | alteira[.]digital |
SourTrade domain IOC | |||
| Domain | dalasu[.]digital |
SourTrade domain IOC | |||
| Domain | parixaxj[.]com |
SourTrade domain IOC | |||
| Domain | trustconnect[.]digital |
SourTrade domain IOC | |||
| Domain | torvianet[.]site |
SourTrade domain IOC | |||
| Domain | nebive[.]site |
SourTrade domain IOC | |||
| Domain | forecastlogiccore[.]digital |
SourTrade domain IOC | |||
| Domain | netkorava[.]digital |
SourTrade domain IOC | |||
| Domain | forecasthub[.]digital |
SourTrade domain IOC | |||
| Domain | dotlor[.]site |
SourTrade domain IOC | |||
| Domain | koravaje[.]digital |
SourTrade domain IOC | |||
| Domain | signalmetrics[.]digital |
SourTrade domain IOC | |||
| Domain | forecastbridge[.]digital |
SourTrade domain IOC | |||
| Domain | lakorava[.]digital |
SourTrade domain IOC | |||
| Domain | pustou[.]site |
SourTrade domain IOC | |||
| Domain | insightorbithub[.]digital |
SourTrade domain IOC | |||
| Domain | dataroutehub[.]digital |
SourTrade domain IOC | |||
| Domain | datasyncengine[.]digital |
SourTrade domain IOC | |||
| Domain | forecastdeltaflow[.]digital |
SourTrade domain IOC | |||
| Domain | forecastlogicflow[.]digital |
SourTrade domain IOC | |||
| Domain | metricforge[.]digital |
SourTrade domain IOC | |||
| Domain | forecastpulsegrid[.]digital |
SourTrade domain IOC | |||
| Domain | robejj[.]com |
SourTrade domain IOC | |||
| Domain | predictcore[.]digital |
SourTrade domain IOC | |||
| Domain | dataplanehub[.]site |
SourTrade domain IOC | |||
| Domain | oneclickme[.]site |
SourTrade domain IOC | |||
| Domain | prolega[.]site |
SourTrade domain IOC | |||
| Domain | nameprod[.]site |
SourTrade domain IOC | |||
| Domain | transoe[.]site |
SourTrade domain IOC | |||
| Domain | orientstrategypartners[.]digital |
SourTrade domain IOC | |||
| Domain | beamoramag[.]digital |
SourTrade domain IOC | |||
| Domain | beammaybea[.]digital |
SourTrade domain IOC | |||
| Domain | urbanleafy[.]info |
SourTrade domain IOC | |||
| Domain | brightmosaic[.]info |
SourTrade domain IOC | |||
| Domain | forthlira[.]digital |
SourTrade domain IOC | |||
| Domain | sobeamora[.]digital |
SourTrade domain IOC | |||
| Domain | topbeamora[.]digital |
SourTrade domain IOC | |||
| Domain | mortarora[.]digital |
SourTrade domain IOC | |||
| Domain | lunarohub[.]info |
SourTrade domain IOC | |||
| Domain | worldsol[.]site |
SourTrade domain IOC | |||
| Domain | mindflowbase[.]info |
SourTrade domain IOC | |||
| Domain | insight-radiant[.]digital |
SourTrade domain IOC | |||
| Domain | nordexastudio[.]info |
SourTrade domain IOC | |||
| Domain | cognitionpipeline[.]digital |
SourTrade domain IOC | |||
| Domain | cognitionnodehub[.]digital |
SourTrade domain IOC | |||
| Domain | acuitycore[.]digital |
SourTrade domain IOC | |||
| Domain | radiantsynaptic[.]digital |
SourTrade domain IOC | |||
| Domain | sapience-flare[.]digital |
SourTrade domain IOC | |||
| Domain | engineclaritynode[.]digital |
SourTrade domain IOC | |||
| Domain | flare-hub[.]digital |
SourTrade domain IOC | |||
| Domain | beacon-net[.]digital |
SourTrade domain IOC | |||
| Domain | brainyclevercore[.]digital |
SourTrade domain IOC | |||
| Domain | syscodeapi[.]digital |
SourTrade domain IOC | |||
| Domain | asiadataintelligencelab[.]digital |
SourTrade domain IOC |
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.