SourTrade Malvertising Makes Browsers Assemble Windows Malware
The Hacker News reported that Confiant analysed SourTrade, a malvertising campaign that uses fake trading pages and browser-side assembly to vary Windows malware files for retail trading and crypto targets.

A malvertising campaign is using the browser as the assembly point for Windows malware, reducing the value of simple file-hash blocking without removing the need for network-level detection.
The Hacker News reported that Confiant analysed the SourTrade operation, which targets retail traders and cryptocurrency investors through fake trading-service pages.
Confiant's July 23 analysis said the campaign had operated since late 2024, impersonating TradingView, Solana and Luno across 12 countries and 25 languages.
The researchers described a staged delivery chain built around visitor filtering and a legitimate runtime component, rather than exploitation of a disclosed browser flaw.
SourTrade Targets Traders With Fake Service Pages
The campaign begins with ads that route users towards pages mimicking trading or crypto services.
Selected visitors see the impersonated site, while suspected researchers or bots receive an empty page.
That screening step makes the operation harder to inspect from a single URL because different visitors do not necessarily receive the same content.
The fake services match workflows where victims may already expect downloads, account tools or wallet-related software.
The article's safest user-level defence is basic but specific: install trading and wallet tools from the vendor's own site rather than from an advertisement.
Browser Assembly Changes The Detection Surface
The delivery chain separates the final Windows file into components that are put together on the victim side.
The browser obtains a legitimate Bun runtime and combines it with attacker-controlled material delivered through the campaign infrastructure, so defenders may not see one finished malware file moving across the network.
The technique changes what defenders can observe without demonstrating a browser exploit.
Confiant did not identify a browser bug or report that Mark of the Web was removed.
Its analysis also did not establish whether the final download starts automatically or requires a user click.
Per-session file variation can still weaken hash-based detection because each generated file may differ.
Attribution Remains Unresolved
Confiant published three SHA-256 hashes and a malicious-domain list that The Hacker News counted at 96 domains, but did not name the actor behind the operation.
Bitdefender reported on a related TradingView malvertising cluster in September 2025; that earlier account did not mention Bun, so its description of payload capabilities cannot establish what the current files do.
Security teams therefore need to correlate ad referrals, cloaked landing pages, runtime retrieval, generated downloads and endpoint records.
The available research identifies the delivery chain but leaves the operator and confirmed post-download behaviour unresolved.














