SourTrade malvertising campaign impersonating trading and cryptocurrency brands
Campaign
Summary
Hide ▲
Show ▼
The SourTrade malvertising campaign remains active, using lookalike portals and malicious JavaScript to target retail traders and cryptocurrency investors across 12 countries and 25 languages. It impersonates brands such as Solana, Luno, and TradingView to lure victims from ads on Facebook and Google. The delivery chain shifts malware assembly into the browser, increasing stealth and complicating detection. The activity has continued since late 2024 and overlaps with related JSCeal distribution.
Related Happenings
JSCeal malware activity
Malware Activity
H score29
First: 07.09.2026 10:53
Last: 07.09.2026 10:53
Sources 1
How related:
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.
About this happening:
JSCeal is a compiled V8 JavaScript malware that now stands out for credential harvesting, session replay, and traffic interception against browser data. The ma...
JSCeal malware activity
Malware ActivityHow related: Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities.
About this happening: JSCeal is a compiled V8 JavaScript malware that now stands out for credential harvesting, session replay, and traffic interception against browser data. The ma...
SourTrade malvertising campaign targeting retail traders and crypto investors
Campaign
H score30
First: 25.07.2026 18:21
Last: 25.07.2026 18:21
Sources 1
About this happening:
The SourTrade malvertising campaign targets retail traders and cryptocurrency investors by impersonating TradingView, Solana, and Luno. It operates across 12 countries and 25 lang...
SourTrade malvertising campaign targeting retail traders and crypto investors
CampaignAbout this happening: The SourTrade malvertising campaign targets retail traders and cryptocurrency investors by impersonating TradingView, Solana, and Luno. It operates across 12 countries and 25 lang...
Latest development: 25.07.2026 21:48
On April 30, 2026, the pages in the SourTrade delivery chain loaded StreamSaver.js from the author's GitHub Pages address, showing an earlier streamed-download path that pointed the recorded download source at the library URL.
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
Campaign
H score38
First: 24.07.2026 18:12
Last: 24.07.2026 18:12
Sources 1
About this happening:
BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
BlueNoroff ClickFix-style Zoom and Microsoft Teams phishing campaign
CampaignAbout this happening: BlueNoroff's ClickFix-style phishing campaign is using typosquatted Zoom and Microsoft Teams domains to deliver malware and steal Telegram sessions from high-value cry...
Lurking Lizard trojanized 7-Zip installer campaign
Campaign
H score84
First: 09.07.2026 07:01
Last: 09.07.2026 07:01
Sources 1
About this happening:
A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
Lurking Lizard trojanized 7-Zip installer campaign
CampaignAbout this happening: A Lurking Lizard campaign used a trojanized 7-Zip installer to recruit devices as proxy nodes, expanding a residential-proxy operation that has run since at least Au...
REF8372 malicious Google Ads CastleStealer delivery campaign
Campaign
H score27
First: 22.06.2026 16:20
Last: 22.06.2026 16:20
Sources 1
About this happening:
The REF8372 campaign now uses malicious Google Ads and a fake Node.js download site to deliver OXLOADER and CastleStealer, putting search users at risk of malw...
REF8372 malicious Google Ads CastleStealer delivery campaign
CampaignAbout this happening: The REF8372 campaign now uses malicious Google Ads and a fake Node.js download site to deliver OXLOADER and CastleStealer, putting search users at risk of malw...
Timeline
-
07.09.2026 10:53 2 articles · 3h ago
SourTrade uses lookalike trading portals to assemble malware in victims’ browsers
Campaign Scope UpdateSourTrade malvertising redirects retail traders and cryptocurrency investors from ads on Facebook and Google to lookalike portals impersonating Solana, Luno, and TradingView, where malicious JavaScript directs the browser to build malware in memory instead of downloading a finished payload. The campaign is assessed to have been active since late 2024 across 12 countries and 25 languages, and the activity overlaps with a JSCeal distribution cluster.
Show sources
- JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies — thehackernews.com — 07.09.2026 10:53
- JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies — thehackernews.com — 07.09.2026 10:53