SourTrade is a malvertising campaign that uses cloaked landing pages and per-session file assembly to make victims’ browsers build a Windows executable from components delivered through a legitimate Bun runtime. Confiant says the operation has targeted TradingView, Solana, and Luno users since late 2024 across 12 countries, with the final file varying by session to evade hash-based detection. #SourTrade #TradingView #Solana #Luno #Bun
Keypoints
- SourTrade has been active since late 2024 and targets traders and crypto investors.
- The campaign impersonates TradingView, Solana, and Luno in multilingual malvertising pages.
- The landing pages use fingerprinting to hide from researchers and show content only to selected victims.
- A legitimate Bun runtime is fetched and combined with attacker-controlled data to build the final Windows executable in the browser.
- Each session can produce a different file hash, making simple detection by hash less effective.
Read More: https://thehackernews.com/2026/07/malvertising-sends-malware-in-pieces.html