Find notable cyber news and cases, enriched with sources, timelines, and signals.

SourTrade malvertising campaign targeting retail traders and crypto investors

Campaign
First reported
Last updated
Happening score
H score 30
3 unique sources, 3 articles

Summary

Hide ▲

The SourTrade malvertising campaign targets retail traders and cryptocurrency investors by impersonating TradingView, Solana, and Luno. It operates across 12 countries and 25 languages, with activity reported since late 2024 and concentration in Asia Pacific and Latin America. The campaign’s delivery chain assembles malware locally in the browser to reduce detection, using ServiceWorker and SharedWorker logic to build a unique payload. Earlier reporting also shows an older StreamSaver.js-based download path, indicating an evolving delivery chain that still ends in a Windows executable.

Related Happenings

SourTrade malvertising campaign impersonating trading and cryptocurrency brands

Campaign
H score34 First: 07.09.2026 10:53 Last: 07.09.2026 10:53 Sources 1

About this happening: The SourTrade malvertising campaign remains active, using lookalike portals and malicious JavaScript to target retail traders and cryptocurrency investors across *...

Nimbus Manticore multi-wave aviation and software phishing and SEO poisoning campaign

Campaign
H score36 First: 26.05.2026 10:13 Last: 26.05.2026 10:13 Sources 1

About this happening: Nimbus Manticore's February-April 2026 campaign widened into multi-wave phishing and SEO poisoning, increasing risk to organizations in the U.S., Europe, and the Middle...

FakeWallet crypto wallet phishing campaign targeting users in China

Campaign
H score14 First: 21.04.2026 00:52 Last: 21.04.2026 00:52 Sources 1

About this happening: The FakeWallet campaign is actively distributing 26 malicious apps that impersonate crypto wallets and steal seed phrases, putting users in China at immediate risk...

Latest development: 24.04.2026 14:48

Kaspersky said the FakeWallet campaign is gaining momentum with new tactics, including phishing apps published in the Apple App Store, cold wallet impersonation, and phishing notifications, and suspected it may be the work of threat actors linked to SparkKitty because some infected apps use OCR to steal wallet recovery phrases and the two campaigns share native Chinese-speaking operators and cryptocurrency targeting.

Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse

Malware Activity
H score31 First: 12.02.2026 16:25 Last: 12.02.2026 16:25 Sources 1

About this happening: Atomic MacOS Stealer (AMOS) is being distributed to macOS users through ClickFix-style Terminal prompts that silently download, mount, and launch DMG payloads. In...

Timeline

  1. 25.07.2026 21:48 1 articles · 1mo ago

    SourTrade pages load StreamSaver.js from GitHub Pages

    Technical Analysis Update

    On April 30, 2026, the pages in the SourTrade delivery chain loaded StreamSaver.js from the author's GitHub Pages address, showing an earlier streamed-download path that pointed the recorded download source at the library URL.

    Show sources
  2. 25.07.2026 21:48 3 articles · 1mo ago

    SourTrade makes victims' browsers assemble a Windows executable

    Initial Disclosure

    SourTrade impersonated TradingView, Solana, and Luno to target retail traders and cryptocurrency investors across 12 countries and 25 languages, and its browser-side delivery chain used a legitimate Bun runtime plus ServiceWorker and SharedWorker logic to assemble a final Windows executable from Base64-supplied PE structure and JavaScriptCore bytecode while Mark of the Web remained present.

    Show sources
  3. 25.07.2026 18:21 2 articles · 1mo ago

    SourTrade delivers malware through fake trading pages and browser workers

    Initial Disclosure

    Confiant describes SourTrade as a malvertising campaign that uses fake Solana, Luno, and TradingView pages with malicious JavaScript to make browsers assemble malware in memory for retail traders and crypto investors. The delivery chain registers a service worker, uses a shared worker and a '/config' assembly response to build the payload locally, rotates seed and size parameters to create a unique hash that bypasses static detection, and shifts from earlier StreamSaver delivery to same-origin ServiceWorker handling. The campaign is localized to 25 languages in 12 countries across Asia Pacific and Latin America.

    Show sources