Confiant reported that SourTrade used malvertisements to spread unfinished malware while impersonating TradingView, Solana, and Luno to target retail traders and crypto investors. The investigation uncovered extensive malicious infrastructure, including typosquatting domains, email-connected domains, and IP addresses linked to the campaign, with many already flagged as malicious. #SourTrade #Confiant #TradingView #Solana #Luno
Keypoints
- SourTrade has been active since late 2024 and uses malvertisements to distribute unfinished malware.
- The campaign impersonates TradingView, Solana, and Luno to lure retail traders and crypto investors.
- Researchers identified 96 network IoCs, all of which were domain names, and none appeared to belong to legitimate companies.
- One client IP address communicated with a SourTrade domain through DNS queries in July 2026.
- Four domain IoCs were found in typosquatting groups, suggesting deliberate impersonation infrastructure.
- Fourteen domain IoCs appeared in malicious feeds 139–207 days before they were labeled as IoCs, indicating earlier threat activity.
- Further analysis uncovered 348 email-connected domains and 186 IP addresses tied to the campaign, with most already confirmed malicious.
MITRE Techniques
- [T1036 ] Masquerading – The actors mimicked legitimate brands and used typosquatting domains to appear trustworthy and deceive victims (‘mimicking TradingView, Solana, and Luno’ and domains like ‘beacon-net[.]digital’ and ‘form-engine[.]digital’).
- [T1566 ] Phishing – The campaign used deceptive malvertisements and impersonation to entice targets into engaging with the malicious infrastructure (‘distributed unfinished malware through SourTrade malvertisements’ and ‘go after retail traders and crypto investors’).
- [T1583 ] Acquire Infrastructure – The threat actors built and used large numbers of malicious domains and related infrastructure to support the campaign (’14 domain IoCs that were likely registered with malicious intent’ and ‘348 distinct email-connected domains’).
- [T1071 ] Application Layer Protocol – DNS was used for domain resolution and communication as part of the campaign’s infrastructure (‘one client IP address communicated with the domain IoC … via two DNS queries’ and ‘recorded 2,217 historical domain-to-IP resolutions’).
Indicators of Compromise
- [Domain names] SourTrade network IoCs and infrastructure – form-networktool[.]digital, beacon-net[.]digital, and other 94 domains
- [Domain names] Typosquatting and malicious domains – forgeengine[.]digital, forgeengine[.]net, and other 2 domains in the same groups
- [Domain names] Malicious email-connected domains – alarde[.]digital, balomboa[.]site, and other 129 domains confirmed malicious
- [IP addresses] Malicious infrastructure and resolution targets – 104[.]21[.]0[.]150, 172[.]67[.]129[.]18, and other 184 malicious IPs
- [IP addresses] Client-side DNS activity – one client IP address communicated with form-networktool[.]digital via DNS queries
- [Email addresses] Historical WHOIS contacts linked to infrastructure – 34 unique public email addresses found in 47 domain records