A large online ad scam is sending retail traders and cryptocurrency users to fake Solana, Luno, and TradingView pages that build malware directly inside the victim’s browser before download. Confiant says the SourTrade campaign has run since late 2024 across 25 languages in 12 countries, mainly in Asia Pacific and Latin America, using JavaScript, SharedWorker, and Service Worker features to assemble a unique malicious executable in memory from a clean Bun binary and remote components so no finished file crosses the network.
Why it matters: People looking for trading or crypto software through ads or sponsored search results could end up downloading malware that steals passwords, wallet data, and other sensitive information. Users should avoid ad-linked downloads and get software only from official vendor sites, while defenders should watch for this same-origin browser download technique and fake finance-brand pages.
info@thehackernews.com (The Hacker News)
2026.07.25
98% relevant
This appears to describe the same underlying campaign: malvertising that delivers malware in fragments and reconstructs the executable in the browser, using fake finance and crypto-brand sites as lures.
Bill Toulas
2026.07.25
100% relevant
This article establishes a distinct tracked story by identifying the ongoing SourTrade campaign, its fake branded lures, target population, geographic scope, and the specific in-browser malware assembly method used to evade detection.
← Back to all stories