SourTrade Malvertising Makes Browsers Assemble Unique Executables

The SourTrade malvertising campaign uses victims’ browsers to assemble Windows executables from a legitimate Bun runtime and separately delivered attacker-controlled components. Active since late 2024, the operation impersonates trading and cryptocurrency platforms, fingerprints visitors, and selectively displays malicious pages across 12 countries and 25 languages. ServiceWorkers and SharedWorkers combine executable structures, malicious bytecode, and pseudorandom data to produce unique per-session files, limiting hash-based detection while retaining Mark of the Web. Defenders should monitor the entire delivery chain, while users should download financial software only from official vendor websites.

Reference: thehackernews.com