Connect with us

Cybersecurity

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

Published

on

July 26, 2026 — Cybersecurity researchers have uncovered a sophisticated malvertising campaign called SourTrade that tricks users into downloading malware by making their own web browsers assemble the malicious program piece by piece instead of delivering a complete executable file.

The campaign, which has reportedly been active since late 2024, primarily targets cryptocurrency investors and online traders by impersonating well-known financial platforms, making detection significantly more difficult for traditional security tools.

Fake Trading Websites Used to Target Victims

According to cybersecurity firm Confiant, the attackers create convincing fake versions of popular services such as TradingView, Solana, and Luno.

The malicious advertisements direct users to cloned websites that closely resemble legitimate platforms. Before displaying the fake page, the websites analyze visitors to determine whether they are genuine users or security researchers.

Visitors suspected of being researchers or automated bots are shown harmless blank pages, while real targets receive realistic-looking websites designed to encourage software downloads.

Researchers advise users to download trading or cryptocurrency wallet applications only from official vendor websites instead of clicking advertisements or sponsored search results.

Browser Builds the Malware Instead of Downloading It

Unlike many traditional malware campaigns, SourTrade does not deliver a single malicious executable directly to victims.

Instead, the browser downloads multiple harmless-looking components, including a legitimate Bun runtime, configuration data, and executable fragments. These individual pieces are then combined locally inside the browser to create the final Windows executable.

Because each download session generates a unique version of the file, the malware receives a different digital fingerprint (hash) every time, making simple hash-based antivirus detection much less effective.

Researchers noted that while no complete malware file is transferred over the network, malicious executable components are still delivered as part of the assembly process.

No Browser Vulnerability Exploited

Confiant emphasized that the campaign does not exploit a browser security flaw or bypass Microsoft’s Mark of the Web (MotW) protection.

The investigation focused on how the malware is delivered rather than how it executes after being downloaded. Researchers have not confirmed whether the final download begins automatically or requires user interaction.

Campaign Linked to Earlier Malvertising Activity

The newly identified campaign appears to have evolved from earlier fake TradingView advertising operations documented during 2025.

Previous investigations connected similar campaigns to information-stealing malware capable of stealing login credentials, cryptocurrency wallets, browser data, and other sensitive information.

However, researchers cautioned that they have not yet confirmed whether the latest SourTrade samples contain the same malware payloads.

Security Experts Recommend Monitoring the Entire Attack Chain

Since the malware is assembled dynamically inside the browser, cybersecurity experts recommend monitoring the complete infection process rather than relying solely on file signatures.

Organizations should watch for suspicious advertising referrals, fake landing pages, unusual configuration requests, secondary runtime downloads, and abnormal browser behavior during downloads.

Confiant also released indicators of compromise, including multiple SHA-256 file hashes and dozens of malicious domains, to help security teams identify the campaign.

How Users Can Stay Protected

Security professionals recommend the following precautions:

  • Download software only from official company websites.
  • Avoid clicking sponsored ads for financial platforms and cryptocurrency services.
  • Verify website addresses before downloading any application.
  • Keep antivirus and endpoint protection software updated.
  • Be cautious of unexpected software download prompts, especially from online advertisements.

Researchers continue to investigate the campaign, and no threat actor has yet been publicly identified.

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2023 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO