SourTrade malvertising campaign targeting retail traders and crypto investors
Campaign
Summary
Hide ▲
Show ▼
The SourTrade malvertising campaign targets retail traders and cryptocurrency investors by impersonating TradingView, Solana, and Luno. It operates across 12 countries and 25 languages, with activity reported since late 2024 and concentration in Asia Pacific and Latin America. The campaign’s delivery chain assembles malware locally in the browser to reduce detection, using ServiceWorker and SharedWorker logic to build a unique payload. Earlier reporting also shows an older StreamSaver.js-based download path, indicating an evolving delivery chain that still ends in a Windows executable.
Related Happenings
SourTrade malvertising campaign impersonating trading and cryptocurrency brands
Campaign
H score34
First: 07.09.2026 10:53
Last: 07.09.2026 10:53
Sources 1
About this happening:
The SourTrade malvertising campaign remains active, using lookalike portals and malicious JavaScript to target retail traders and cryptocurrency investors across *...
SourTrade malvertising campaign impersonating trading and cryptocurrency brands
CampaignAbout this happening: The SourTrade malvertising campaign remains active, using lookalike portals and malicious JavaScript to target retail traders and cryptocurrency investors across *...
Nimbus Manticore multi-wave aviation and software phishing and SEO poisoning campaign
Campaign
H score36
First: 26.05.2026 10:13
Last: 26.05.2026 10:13
Sources 1
About this happening:
Nimbus Manticore's February-April 2026 campaign widened into multi-wave phishing and SEO poisoning, increasing risk to organizations in the U.S., Europe, and the Middle...
Nimbus Manticore multi-wave aviation and software phishing and SEO poisoning campaign
CampaignAbout this happening: Nimbus Manticore's February-April 2026 campaign widened into multi-wave phishing and SEO poisoning, increasing risk to organizations in the U.S., Europe, and the Middle...
FakeWallet crypto wallet phishing campaign targeting users in China
Campaign
H score14
First: 21.04.2026 00:52
Last: 21.04.2026 00:52
Sources 1
About this happening:
The FakeWallet campaign is actively distributing 26 malicious apps that impersonate crypto wallets and steal seed phrases, putting users in China at immediate risk...
FakeWallet crypto wallet phishing campaign targeting users in China
CampaignAbout this happening: The FakeWallet campaign is actively distributing 26 malicious apps that impersonate crypto wallets and steal seed phrases, putting users in China at immediate risk...
Latest development: 24.04.2026 14:48
Kaspersky said the FakeWallet campaign is gaining momentum with new tactics, including phishing apps published in the Apple App Store, cold wallet impersonation, and phishing notifications, and suspected it may be the work of threat actors linked to SparkKitty because some infected apps use OCR to steal wallet recovery phrases and the two campaigns share native Chinese-speaking operators and cryptocurrency targeting.
Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse
Malware Activity
H score31
First: 12.02.2026 16:25
Last: 12.02.2026 16:25
Sources 1
About this happening:
Atomic MacOS Stealer (AMOS) is being distributed to macOS users through ClickFix-style Terminal prompts that silently download, mount, and launch DMG payloads. In...
Atomic MacOS Stealer (AMOS) distribution through AI-app lures, SEO poisoning, and supply-chain abuse
Malware ActivityAbout this happening: Atomic MacOS Stealer (AMOS) is being distributed to macOS users through ClickFix-style Terminal prompts that silently download, mount, and launch DMG payloads. In...
Timeline
-
25.07.2026 21:48 1 articles · 1mo ago
SourTrade pages load StreamSaver.js from GitHub Pages
Technical Analysis UpdateOn April 30, 2026, the pages in the SourTrade delivery chain loaded StreamSaver.js from the author's GitHub Pages address, showing an earlier streamed-download path that pointed the recorded download source at the library URL.
Show sources
- Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable — thehackernews.com — 25.07.2026 21:48
-
25.07.2026 21:48 3 articles · 1mo ago
SourTrade makes victims' browsers assemble a Windows executable
Initial DisclosureSourTrade impersonated TradingView, Solana, and Luno to target retail traders and cryptocurrency investors across 12 countries and 25 languages, and its browser-side delivery chain used a legitimate Bun runtime plus ServiceWorker and SharedWorker logic to assemble a final Windows executable from Base64-supplied PE structure and JavaScriptCore bytecode while Mark of the Web remained present.
Show sources
- Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable — thehackernews.com — 25.07.2026 21:48
- Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable — thehackernews.com — 25.07.2026 21:48
- SourTrade Malvertising Campaign Secretly Builds Malware in the Browser — www.infosecurity-magazine.com — 27.07.2026 14:30
-
25.07.2026 18:21 2 articles · 1mo ago
SourTrade delivers malware through fake trading pages and browser workers
Initial DisclosureConfiant describes SourTrade as a malvertising campaign that uses fake Solana, Luno, and TradingView pages with malicious JavaScript to make browsers assemble malware in memory for retail traders and crypto investors. The delivery chain registers a service worker, uses a shared worker and a '/config' assembly response to build the payload locally, rotates seed and size parameters to create a unique hash that bypasses static detection, and shifts from earlier StreamSaver delivery to same-origin ServiceWorker handling. The campaign is localized to 25 languages in 12 countries across Asia Pacific and Latin America.
Show sources
- Malicious sites use JavaScript to build malware in browser memory — www.bleepingcomputer.com — 25.07.2026 18:21
- Malicious sites use JavaScript to build malware in browser memory — www.bleepingcomputer.com — 25.07.2026 18:21