The landscape of malvertising has undergone a disturbing evolution, shifting away from the direct delivery of malicious binaries toward a more insidious model where the victim's own device acts as the assembly line. Security researchers at Confiant have uncovered a sophisticated campaign, tracked as SourTrade, which exemplifies this dangerous trend by manipulating web browsers into constructing malware locally rather than downloading a pre-built executable. This discovery highlights a growing maturity in attacker methodologies, aiming to subvert traditional detection mechanisms by fragmenting the threat delivery process and forcing the client to do the heavy lifting.
Active since late 2024, the SourTrade operation specifically targets retail traders and individuals involved in the cryptocurrency ecosystem. The attackers entice victims by impersonating well-known financial entities, including TradingView, Solana, and Luno. Once a user engages with the malicious advertisement, the attack chain does not immediately serve a complete malicious file from a fixed URL. Instead, the campaign sends the malware in separate, fragmented pieces to the victim’s browser. The browser is then coerced into utilizing a legitimate instance of the Bun runtime as a base to assemble these fragments into a functional Windows executable. This method effectively turns the victim’s browser into a compiler for the malware, bypassing defenses that look for completed file downloads or static indicators of compromise.
Comments (0)
Leave a Comment
No comments yet. Be the first to comment!