Connect with us

Cybersecurity

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

Published

on

A sophisticated online advertising campaign is using a new malware delivery method that allows victims’ own web browsers to assemble malicious Windows files, making traditional detection methods significantly less effective.

According to cybersecurity researchers at Confiant, the operation—tracked under the name SourTrade—has been active since late 2024 and primarily targets cryptocurrency investors and online traders. The campaign disguises itself as trusted financial platforms, including TradingView, Solana, and Luno, to trick users into downloading seemingly legitimate software.

Malware Built Inside the Browser

Unlike conventional malware attacks that distribute a complete executable file from a single server, SourTrade delivers multiple harmless-looking components separately. The victim’s browser then combines these pieces into a working Windows executable using the legitimate Bun runtime.

Researchers say this technique helps attackers avoid detection because the complete malware file is never transmitted across the internet in one piece. Instead, each download session generates a unique executable, making simple hash-based security checks far less effective.

Sophisticated Evasion Tactics

The attackers use advanced fingerprinting technology to determine who visits their fake websites. Security researchers, automated scanning tools, and bots are often shown blank or harmless pages, while intended victims receive convincing replicas of legitimate cryptocurrency and trading platforms.

This selective targeting allows the campaign to remain active for longer periods without attracting immediate attention from security analysts.

How the Attack Works

Confiant’s investigation found that the malicious websites prepare the download process immediately after a visitor lands on the page.

The browser first creates background workers that silently retrieve configuration data from attacker-controlled servers. It then downloads a clean version of the Bun runtime from a secondary domain before combining it with additional executable components delivered in encoded form.

The browser also generates randomized data during the assembly process, ensuring that each resulting executable has a different digital fingerprint even though the underlying malicious code remains functionally similar.

After the file is assembled, it is delivered through the browser using a Service Worker, allowing the download to appear as though it originated from the landing page itself rather than the external server hosting some of the components.

No Browser Vulnerability Required

Researchers emphasized that the campaign does not exploit browser security flaws or bypass Microsoft’s Mark of the Web (MotW) protection. Instead, it relies on legitimate browser features combined with social engineering techniques to persuade users to download and run the generated file.

The study also notes that the malware delivery chain focuses on creating and downloading the executable rather than executing it automatically.

Links to Earlier Malvertising Campaigns

Security experts believe the operation shares similarities with earlier malicious advertising campaigns documented during 2025. Previous investigations connected related activity to malware capable of credential theft, cryptocurrency wallet theft, keylogging, remote access, and network traffic interception.

However, Confiant cautioned that it has not confirmed whether the latest SourTrade samples carry the exact same malware payloads identified in earlier campaigns.

Security Recommendations

Since the attack relies heavily on deceptive online advertisements rather than software vulnerabilities, there is currently no security patch that can prevent this specific technique.

Cybersecurity professionals recommend several best practices to reduce risk:

  • Download trading and cryptocurrency wallet applications only from official vendor websites.
  • Avoid clicking software advertisements displayed through search engines or third-party websites.
  • Monitor suspicious browser activity involving Service Workers and unusual download behavior.
  • Use modern endpoint security solutions capable of analyzing complete attack chains rather than relying solely on file hashes.

Confiant also released multiple SHA-256 hashes and dozens of malicious domains associated with the campaign to assist defenders in identifying related activity. At this time, the researchers have not attributed the operation to any specific threat actor.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO