SourTrade malvertising campaign targeting retail traders and crypto investors
Campaign
Updated: 25.07.2026 18:21
· First: 25.07.2026 18:21
· 📰 1 src / 1 articles
· H score: 30
The SourTrade malvertising campaign now uses fake Solana, Luno, and TradingView pages with malicious JavaScript to assemble malware in browser memory, reducing detection and widening risk for retail traders and crypto investors. It has been active since late 2024 and operates across 25 languages in 12 countries, mainly in Asia Pacific and Latin America. The current delivery flow uses ServiceWorker and SharedWorker logic to build a unique payload locally and evade static detection.