SourTrade turns browsers into covert malware factories

A malvertising operation targeting traders and cryptocurrency users is assembling malicious Windows software inside victims’ browsers, allowing each downloaded file to evade conventional fingerprint-based security checks.

The campaign, known as SourTrade, uses sponsored advertisements and imitation websites resembling TradingView, Solana and Luno. Rather than transmitting a complete malicious program, the sites send instructions and separate components that the browser combines into an executable file on the user’s device.

The technique represents a significant change in malware delivery. Network security products inspecting downloaded files may encounter only legitimate software, small data fragments or encrypted instructions. The malicious executable takes its final form in browser memory, after those elements have crossed the network separately.

SourTrade has operated since late 2024 and has targeted users in 12 countries through advertisements and websites presented in 25 languages. Observed markets include Japan, Thailand, South Korea, Taiwan, Hong Kong, Bolivia, Brazil, Nigeria, Türkiye, South Africa, Australia and Great Britain.

The operators appear focused on retail investors who routinely search online for market-analysis tools, cryptocurrency services and trading applications. Users following promoted links can be directed to carefully designed replicas of familiar platforms and encouraged to download what appears to be legitimate software.

TradingView, Solana and Luno have not been identified as sources of the malware. Their branding is being copied by attackers seeking to exploit trust in established financial and cryptocurrency services.

The landing pages employ cloaking technology to distinguish likely victims from automated scanners, advertising reviewers and cybersecurity analysts. Selected users see a convincing product page, while suspected researchers or bots may receive an empty or harmless page. This selective delivery makes the campaign harder to reproduce and investigate.

Browser scripts begin preparing the delivery mechanism even before a user presses the download button. The page registers a ServiceWorker, a legitimate browser feature capable of managing network requests and streamed content. It also creates a SharedWorker from JavaScript embedded within the page.

The SharedWorker requests a configuration file containing an assembly template, session-specific random values and the location of a legitimate Bun runtime. Bun is a high-performance JavaScript and TypeScript development toolkit. There is no evidence that its developers or distribution infrastructure were compromised.

The browser retrieves the clean Bun component and combines it with attacker-controlled data, a Windows Portable Executable structure and malicious JavaScriptCore bytecode. It also generates pseudorandom data through AES counter-mode operations, using values supplied for that particular session.

These changing bytes make the resulting executable different for each victim or download. Its cryptographic hash therefore varies, weakening security systems that depend on matching files against lists of known malware fingerprints.

Once assembly is complete, the ServiceWorker supplies the finished stream through a download address belonging to the imitation website. The browser presents it as an ordinary attachment originating from the same domain, although important components came from separate infrastructure.

The downloaded program does not automatically execute merely because the landing page was opened. Infection generally requires the user to download and run the resulting Windows executable. Entering credentials, approving cryptocurrency transactions or connecting a wallet to an imitation platform could create additional exposure.

The campaign’s websites contain advertising and tracking elements associated with Google Ads, Meta platforms and X. Those components indicate that the operators may be measuring traffic and refining their targeting across several advertising ecosystems, although their presence alone does not establish that every platform carried malicious advertisements.

Earlier versions used StreamSaver-based methods and could leave download-origin records pointing towards GitHub-hosted helper infrastructure. Variants observed after April shifted towards same-origin delivery, giving the final file a more ordinary-looking browser provenance record.

SourTrade exposes weaknesses in security models centred on inspecting complete files during transmission. Effective detection may require endpoint and browser telemetry capable of connecting suspicious advertising redirects, ServiceWorker registration, unusual runtime downloads and the subsequent creation of executable files.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
OPPO Find X10 Pro Max to Debut Globally with MediaTek’s 2nm Flagship Dimensity 9600 Pro // Almarai earmarks $4 billion for expansion through 2031 // Wikimedia identifies unauthorised OpenAI agent activity across platforms // Trump-Newsom Clash Assumes Special Significance Before Nov 3 Polls // Lufthansa and three airlines halt Riyadh flight operations // OpenAI extends GPT-6 access with interactive ChatGPT interface // ONYX Hospitality Group Marks 60 Years with Curated Partnerships Bringing “More of What You Love” to Life // Dubai property sales slump as war pressures prices // Two Bypoll Results In Bengal Vindicate State BJP’s Success In Courting Minorities // React flaw exposes Next.js servers to service disruption // Ping An Digital Bank Becomes Hong Kong’s First Digital Bank to Enter High-End Wealth Management Segment // Bypoll Results In Bengal And Assam Underline BJP’s Expansion In Eastern Region // Abu Dhabi climate summit records over 1,000 registrations // BINGXUE Opens First U.S. Store in Davis, California: Shandong’s First Mass-Market Tea Beverage Brand Enters North America // UK and allies expose Integrity Tech cyber operations // Prudential Singapore launches multi-generational protection plan to help caregivers manage families’ healthcare needs // Anti-Election Commission Protest: Athletic Rahul Steals The Show // Malicious GitHub workflows expose credentials across hundreds of repositories // Oriental Residence Bangkok Awarded One MICHELIN Key for the Third Consecutive Year // Saudi Arabia and UAE endorse Japan’s Asian oil initiative //