A large malvertising campaign is abusing fake Solana, Luno, and TradingView pages to make browsers assemble malware locally in memory, helping the payload evade detection. The operation, linked to the SourTrade campaign, targets retail traders and crypto investors across 25 languages and 12 countries, while using unique session-specific builds to bypass static analysis. #Solana #Luno #TradingView #SourTrade #Bitdefender
Keypoints
- Fake Solana, Luno, and TradingView pages are used to lure victims.
- Malicious JavaScript makes the browser assemble malware in memory.
- The campaign has been active since late 2024 across 25 languages and 12 countries.
- Researchers and security bots are redirected to blank pages by filtering checks.
- Session-specific builds and same-origin delivery help evade static detection.